- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-08-2021 03:10 PM
Thank you @ChrisKarakostas for posting question.
To my knowledge it is not possible. In the security policy, you can use only AD Groups or Users.
Here is the link for Documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-users-to-groups.html You can configure the Base-DN in LDAP profile for entire AD Domain, however when you configure Group Mapping Setting only Group Objects and User Objects are available and this is what you will end up using as source user in a security policy.
If you are setting this up for the first time from scratch, below are a few KBs for reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGOCA0
Note: After you complete the LDAP profile and Group Mapping Setting with user/group include list, you will have to commit it first before you can select user/group as a source in the security policy.
If you get stuck with the setup do not hesitate to post your problem here, I will do my best to help.
Kind Regards
Pavel