- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-03-2021 11:29 AM
Hi @JorgeOrtega ,
The authentication sequence should check both authentication profiles regardless of the AAA response -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMdXCAW. (The link on the bottom of that link provides more details.) I would double check that the user is not failing via LDAP also.
With regard to groups, you can configure groups in the authentication profile under Advanced. The groups configured under Device > User Identification > Group Mapping Settings > [edit group] > Group Include List will show in the authentication profile. The firewall does an LDAP query for the group and gets the users. If the login username matches, then the profile is used.
With regard to NPS, the Event Log > Security should tell you why it is failing.
Thanks,
Tom