Plugin Validation error during Commit after configuring Directory Sync Alternate User Name

Plugin Validation error during Commit after configuring Directory Sync Alternate User Name

3243
Created On 07/27/22 18:09 PM - Last Modified 09/20/24 02:30 AM


Symptom


  • Alternate User name configured in Directory Sync Integration.
  • plugin_cloud_services.log (less plugin-log plugin_cloud_services.log) displays the following error during the commit process.
>ERROR: [validation] Errors: User attribute onPremisesUserPrincipalName in Prisma Access Group Mapping is not available in Directory Sync.


Environment


  • Panorama managed Prisma Access
  • Directory Sync


Cause


Unsupported directory attribute.

Resolution


  1. Remove the attribute listed in the plugin_cloud_services.log . In this case it is "onPremisesUserPrincipalName".
  2. Not all attributes on AD are supported on Prisma Access. The following chart is the list of supported attributes.
NAMEDIRECTORY ATTRIBUTE
Common-Namecn
Countryco
Departmentdepartment
Distinguished Namedn
GroupsmemberOf
Last LoginlastLogon
LastLogonTimelastLogonTimestamp
Locationl
MSDSAllowedDelegatedTomsDS-AllowedToDelegateTo
MSDSAllowedToActOnBehalfOfOtherIdentitymsDS-AllowedToActOnBehalfOfOtherIdentity
MSDSSupportedEncryptionTypesmsDS-SupportedEncryptionTypes
Mailmail
Managermanager
NETBIOS NamenETBIOSName
NamedisplayName
Object ClassobjectClass
Primary Group IDprimaryGroupID
SAM Account NamesAMAccountName
SIDobjectSid
SID HistorysIDHistory
Service Principal Name"servicePrincipalName
Titletitle
Unique IdentifierobjectGUID
User Principal NameuserPrincipalName
UserAccountControluserAccountControl
WhenChangedwhenChanged
WhenCreatedwhenCreated


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wl8NCAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language