Hi @tamilvanan , Does the username format in the "show user ip-user-mapping all" command match the username format in the "show user group name cn=blah,cn=blah,dc=blah,dc=blah" command? (The "show user group list" command will give you the exact group name for the previous command.) If the format does not match exactly, then the user may not be matched to the group. There are some things you can do to fix the issue: Make sure the domain specified under Device > Authentication Profile > [LDAP Authenticaton Profile] > Authentication > User Domain matches the domain under Device > User Identification > Group Mapping Settings > [edit] > Server Profile. Follow the guidelines in this doc -> https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/user-id-features/support-for-multiple-username-formats. The primary and alternate usernames can fix it as well as the matching without domains if the domain is different or missing. Thanks, Tom
... View more