ldap user group unable to get access

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

ldap user group unable to get access

L3 Networker

I have ldap server setup with auth profile. User gets authenticate by ldap server and can login via global protect.

User is part og the group and a policy is created for this group to access resources.

If i change the group to any access is granted but not with specific group in policy.


Cyber Elite
Cyber Elite


Have you verified that the group is in the group-include list? 

L7 Applicator

also... remember that adding users to groups can take up to 45 mins to replicate to Palo.


this will force an update...


debug user-id refresh group-mapping all



to see your included groups


show user group list


to list known users in a group


show user group name "group-name-from-above-command"

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!