Is it possible to create AD group based authentication for PaloAlto administrators?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Is it possible to create AD group based authentication for PaloAlto administrators?

L4 Transporter

Hi All,.

Is it possible to create AD group based authentication for PaloAlto administrators?

If yes, kindly provide the steps for the same.

Regards,

Gururaj

4 REPLIES 4

L5 Sessionator

Hi,

If your question is about using a group instead of users for admin, answer is no .... not yet

Else for sure you can group all your pa'sadmin in AD group and use all user in this group for defining admin profile and role.

What you have to do is to follow this doc: https://live.paloaltonetworks.com/docs/DOC-4740,create your admin account in the palo then assign them to admin role.

Hope help

V.

You can use Radius VSA to accomplish group permission for admin.  Here's a doc on Radius VSA and configuration examples for Windows server: Radius Vendor Specific Attributes (VSA) .

Thanks.

L5 Sessionator

If you are planning to use a group name under Device ---> administrator then it wont work

You have to user individual user names with LDAP as authentication profile.

Step1:

create LDAP profile

Device --> Server Profiles ---> LDAP

Capture.JPG.jpg

Step2:

Create authentication profile under Device --> Authentication Profiles

Capture.JPG.jpg

Step3:

Now select under Device --> administrator

Create an Administrator user. Make sure the user name is same as on the DC other wise the user will not able able to login.

Capture.JPG.jpg

Now commit the changes and the user will be able to login.


However if this is not feasible for you and you do not want to configure all you users here . You can also use Radius and set it with Admin Roles.

Here is a doc that explains how to do that.

https://live.paloaltonetworks.com/docs/DOC-1765

Hope this helps.

Thanks

Numan

L5 Sessionator

Here is another doc which explains on how to setup LDAP authentication

https://live.paloaltonetworks.com/docs/DOC-2910

Let us know if this helps.
Thanks

Numan

  • 2331 Views
  • 4 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!