Not able to select "Authentication profile (Non-UI)" under Authentication settings
2371
Created On 11/30/22 06:16 AM - Last Modified 07/12/25 02:18 AM
Symptom
- Radius (or Tacacs+) authentication profile is selected under GUI: Device > Setup > Management > Authentication Settings
- The next setting of "Authentication Profile (Non-UI)" cannot be selected and is grayed out.
Environment
- Palo Alto Firewall
- PAN-OS 10.1
- RADIUS/TACACS is configured for Authentication Profile
Cause
Non-UI authentication profile is activated only when SAML or Cloud Authentication Service is configured for Authentication Profile.
Resolution
To configure RADIUS as Non-UI, select SAML or Cloud Authentication Service for Authentication Profile.
- Create a SAML OR Cloud Authentication Service Authentication Profile
- GUI: Device> Setup> Management> Authentication Settings set Authentication Profile to SAML.
- From Authentication Profile (Non-UI) select drop down menu and select the RADIUS profile
- Click OK
- Commit
Example setting shown below
Additional Information
Authentication Settings
| Auth profile | Auth profile |
|---|---|
| X | X |
| RADIUS | X |
| TACACS+ | X |
| SAML | RADIUS/TACPLUS |
| Cloud Authentication Service | RADIUS/TACPLUS |
Note: X is None or grayed out