User ID with Mapped Drives Mapping to Wrong Users

User ID with Mapped Drives Mapping to Wrong Users

16512
Created On 09/25/18 19:25 PM - Last Modified 11/06/20 22:30 PM


Symptom

User Identification with mapped drives mapping to wrong users.



Environment
  • Any PAN-OS.
  • Palo Alto Firewall.
  • Windows User-ID Agent.
  • Integrated User-ID Agent (7.1 and above only)


Cause

When using User Identification with mapped drives, issues may occur where the user is being seen as the user you logged into your drive as.  This is working as designed.

The user to IP mapping occurs from the Active Directory mapping and from login events.  If a new event is created then you will see the new mapping and that user will have access allocated by that user.



Resolution

The workaround for this issue is to add the user to the ignore list on the agent.  Refer to How to Ignore Users in User-ID Agent.

 

 



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/kcsArticleDetail?id=kA10g000000ClY9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcsArticleDetail

Attachments
Choose Language