The User-ID software reads user and group information from an Active Directory server and forwards the learned information to a Palo Alto Networks firewall to allow using domain user and group-based policies.
This document covers the configuration required when NetBIOS probing is disabled. Disabling the NetBIOS probing option is recommended when the workstations are not allowing remote netBIOS probes.
The recommended timeout setting is a time equal to or longer than the domain timeout. The default windows domain idle timeout is 8 hrs. Set the timeout to 8 hours or longer.