如何禁用用户 ID 代理的凭据强制状态

如何禁用用户 ID 代理的凭据强制状态

2446
Created On 04/23/25 22:29 PM - Last Modified 05/02/25 08:30 AM


Objective


禁用User-ID 代理的凭据强制执行状态



Environment


  • User-ID 代理
  • 凭证代理


Procedure


  1. 在安装了User-ID 代理的RODC 上,启动 User-ID 代理应用程序。
  2. 选择设置并编辑设置部分。
  3. 选择“凭据”选项卡。仅当您已安装 User-ID 代理凭据服务时才会显示此选项卡。
  4. Credential Agent
  5. 确保“从文件导入”和“从用户 ID 凭证代理导入”都未被选中。
  6. To ensure that you have indeed disabled the credential enforcement on the user ID agent, issue the CLI command from the firewall:
    > show user user-id-agent state <name of the UIA> | match Agent\|Status
  7. Example output:
    > show user user-id-agent state rodc-1 | match Agent\|Status
    Agent: rodc-1(vsys: vsys1) Host: rodc-1.domain.lab(10.1.1.254):5007
            Status                                            : conn:idle
                 Credential Enforcement Status : Disabled
    


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000TN6PKAW&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language