Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A company is implementing User-ID to enforce user-based security policies. After configuring the User-ID agent on a Windows server to monitor the domain controller's security logs, users are still being identified as 'unknown' in the firewall's logs. What is the most likely reason for this issue?

  1. AThe firewall does not have a security policy rule allowing traffic from the User-ID agent to the firewall, or vice-versa.
  2. BThe User-ID agent is installed on a domain member server instead of the domain controller.
  3. CThe firewall does not have connectivity to the Active Directory domain controller.
  4. DThe User-ID agent does not have the necessary permissions to read the security event logs on the domain controller.
Show answer & explanation

Correct answer: D. The User-ID agent does not have the necessary permissions to read the security event logs on the domain controller.

For the User-ID agent to collect user-to-IP mappings from Windows security event logs, it requires specific permissions (e.g., 'Event Log Readers' group membership) to access those logs on the domain controllers. If these permissions are missing, the agent cannot collect the necessary information, leading to 'unknown' users.

Why the other options are wrong

  • A. While network connectivity is essential, the question states the agent is 'monitoring' the logs, implying it's running. Lack of permissions is a more direct cause for 'unknown' users if the agent can reach the DC.
  • B. The User-ID agent can be installed on a domain member server, as long as it has network access and correct permissions to the domain controllers it monitors.
  • C. Lack of connectivity to the domain controller would prevent the agent from even attempting to monitor logs. The issue is that it's 'monitoring' but not 'collecting' effectively, pointing to permissions.

User-ID Agent Permissions

The Palo Alto Networks User-ID agent requires specific permissions on domain controllers to read security event logs and collect user-to-IP address mappings.

  • Agent needs 'Event Log Readers' group membership on domain controllers.
  • WMI access may also be required for certain User-ID features.
  • Lack of permissions prevents the agent from collecting user mapping data.
  • User-ID relies on successful collection of these mappings to identify users.

Memory trick: User-ID: Know your users, map their IPs, secure their flows.

More Security Policy Configuration questions