Palo Alto drops current local login when using RDP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto drops current local login when using RDP

L0 Member

Hi!

We are currently using a PA500 appliance using User ID Agent on Windows Server 2008 R2.

My profile account (ex. super_user) is exempted to all which means I have no restrictions in accessing any websites.

Apparently, when I RDP our servers I have to login as our admin account (ex. adm_user). After my activity on our servers, I closed RDP and go back to my internet activities but apparently Palo Alto validates my login as adm_user and not super_user anymore.

1 accepted solution

Accepted Solutions

L4 Transporter

That's expected behavior with the current implementation of User-ID. If you logoff logon from your locl machine, User-ID will pick up your correct user name again.

View solution in original post

2 REPLIES 2

L4 Transporter

That's expected behavior with the current implementation of User-ID. If you logoff logon from your locl machine, User-ID will pick up your correct user name again.

A workaround is to add adm_user to the exclude list (that is use a dedicated account for RDP (that means you got two accounts - one to login with and the other to use for RDP)) in the PAN-agent. This way the PAN-agent will ignore adm_user when it login through RDP.

  • 1 accepted solution
  • 1989 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!