Not able to select "Authentication profile (Non-UI)" under Authentication settings

Not able to select "Authentication profile (Non-UI)" under Authentication settings

2371
Created On 11/30/22 06:16 AM - Last Modified 07/12/25 02:18 AM


Symptom


  • Radius (or Tacacs+) authentication profile is selected under GUI: Device > Setup > Management > Authentication Settings
  • The next setting of "Authentication Profile (Non-UI)"  cannot be selected and is grayed out.

NON UI-2.png

 



Environment


  • Palo Alto Firewall
  • PAN-OS 10.1
  • RADIUS/TACACS is configured for Authentication Profile


Cause


Non-UI authentication profile is activated only when SAML or Cloud Authentication Service is configured for Authentication Profile.

Resolution


To configure RADIUS as Non-UI, select SAML or Cloud Authentication Service for Authentication Profile. 
  1. Create a SAML OR Cloud Authentication Service Authentication Profile
  2. GUI: DeviceSetup> Management> Authentication Settings set Authentication Profile to SAML.
  3. From Authentication Profile (Non-UI) select drop down menu and select the RADIUS profile
  4. Click OK
  5. Commit

Example setting shown below

SAML Configured for Authentication Profile
 


Additional Information


Authentication Settings
Auth profile Auth profile 
XX
RADIUSX
TACACS+X
SAMLRADIUS/TACPLUS
Cloud Authentication ServiceRADIUS/TACPLUS

Note: X  is None or grayed out



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sa0ACAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail