My Actual Issue,
GlobalProtect Portal or Agent users fail authentication
My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.
And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC
Model 850, VSYS Not Support, so I skip the "shared" authentication profile here.
when you run a cli auth profile test you need to use domain\username because cli test does not use the domain info in the auth profile. it just ignores it.
also you need to ensure you have the correct setting samaccountname or userprincipalname in both group mapping and the auth profile.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!