Cannot Pull Groups from Active Directory LDAP Server

Cannot Pull Groups from Active Directory LDAP Server

32796
Created On 09/26/18 13:50 PM - Last Modified 06/13/23 16:42 PM


Resolution


Issue

When trying to pull users and groups into the firewall from an Active Directory LDAP server, users and groups do not appear.

When configuring group mapping (Device > User Identification > Group Mapping), the Server Profile drop-down under the Server Profile tab contains no values.

grmapp.PNG

Cause

In order to use the LDAP authentication for logging in admin users only, theĀ  "Administrator Use Only" option for a LDAP server profile (Device > LDAP Server Profile) may have been checked. This prevents the firewall from pulling users and groups. All admin authentication requests will be forwarded to the LDAP server. Authorization, to see whether or not that user is allowed admin privileges, is determined there.

adminuseonly.PNG

Resolution

In order to pull specific groups only and rely on an authentication profile that has specific filtered groups, uncheck the 'Administrator Use Only' option. This ensures that the relevant groups are pulled from the LDAP server. When the option is unchecked, the LDAP server profile will appear under group mappings.

unchecked.PNG

Likewise, you can see them in the Group Include List tab:

group-listing.PNG

You are not restricted to using "All" groups in the authentication profile because specific groups under group mapping would have been pulled correctly. The filtered groups can be applied in the Authentication Profile:

auth.PNG

While the Administrator's log on will refer to this Authentication Profile, note that the name of the Authentication Profile is LDAP under the Administrator's page :

admins.PNG

owner: sjamaluddin



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsSCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language