I had this similar issue and engaged TAC but couldnt find any definitive root cause as to why this issue popped up after we upgraded from 7.1 to 8.1, following the two steps resolved issue for us. 1. Remove User Domain from Group Mapping 2. Removed AD Group in Portal > Agent > User/User Group Root cause is still under investigation but I suspect this has something to do with the way firewall had normalized usernames(Group Mapping) in previous OS. If the Primary Username is in User Principal Name (UPN) format, it will not be normalized in the domain\username format as in previous versions. For example, if the Primary Username is received in the UPN format, it will be displayed as username@domain , not domain\username From : https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/user-id-features/support-for-multiple-username-formats
... View more