- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-24-2025 12:33 AM
local admin created with authentication profile set to none but still PaloAlto is looking for authentication profile for this local user and not allowing to login, saying invalid username/password and here at FW end we are getting the log- Reason: Authentication profile not found for the user
PAN OS - 11.1.10-h1 - Is this is a bug in this version. Is anyone face such issue.
09-29-2025 12:25 AM
@PavelK
To resolved this we have upgrade the PAN-OS and after upgrade the same device were able to accept the new password. In that case it seems to have a new bug for this PAN-OS. Now we are able to change the default admin password and as well as create the new local admin with no authentication profile. Thank you for your time.
09-24-2025 03:22 PM
Hello @P.Singh699426
thanks for post!
Based on release notes there is no known issue corresponding to your post. Could you please run from CLI: tail follow yes mp-log authd.log while logging with that account to see it can provide more details?
Kind Regards
Pavel
09-24-2025 11:18 PM
Hello PavelK,
Thank you for your response. I’ve confirmed that the user is unable to log in via CLI as well. I’ve collected the logs from the CLI for your review. Based on the output, it appears that Palo Alto is attempting to apply an authentication profile to the local admin user — which should not be the case, except for the default admin user.
Please have a look at the logs below and advise further.
2025-09-24 17:44:30.021 +0530 debug: _get_auth_prof_detail(pan_
2025-09-24 17:44:30.021 +0530 Error: pan_auth_cache_get_admin_
2025-09-24 17:44:30.021 +0530 Error: _get_admin_authentication_
2025-09-24 17:44:30.021 +0530 Error: _get_admin_authentication_
09-24-2025 11:27 PM
Hello @PavelK
Please have a look at the logs below and advise further.
2025-09-24 17:44:30.021 +0530 debug: _get_auth_prof_detail(pan_
2025-09-24 17:44:30.021 +0530 Error: pan_auth_cache_get_admin_
2025-09-24 17:44:30.021 +0530 Error: _get_admin_authentication_
2025-09-24 17:44:30.021 +0530 Error: _get_admin_authentication_
09-26-2025 01:37 AM
@PavelK and others,
As checked, I have observed that the local admin user created via the GUI is not visible in the CLI, while the local admin user created via the CLI is visible in the GUI but not properly reflected in the CLI. In other words, users created from either the GUI or CLI are not consistently replicated across both interfaces.
Additionally, we are unable to change the password of the default admin account. Although the firewall commit succeeds, the firewall continues to accept only the old password and rejects the new password as invalid.
09-28-2025 05:25 PM
Hello @P.Singh699426
thank you for reply.
I was going through documentation and based on what I could get out of this page: Local Authentication this looks like expected:
If possible, could you in authentication profile set type to: "Local Database"?
Kind Regards
Pavel
09-29-2025 12:25 AM
@PavelK
To resolved this we have upgrade the PAN-OS and after upgrade the same device were able to accept the new password. In that case it seems to have a new bug for this PAN-OS. Now we are able to change the default admin password and as well as create the new local admin with no authentication profile. Thank you for your time.
09-29-2025 04:27 PM
Hello @P.Singh699426
thank you for reply.
What PAN-OS version did you upgrade to? I went through release notes of PAN-OS 11.1.11 and unfortunately there is no addressed issue corresponding to symptoms you described.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!