nerdexam
Palo_Alto_Networks

PCNSE · Question #407

A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama. Which configuration is necessary to retrieve groups from Panorama?

The correct answer is D. Configure a master device within the device groups. To use Active Directory groups in Panorama security policies, Panorama must have a way to retrieve and display those groups. This is accomplished by configuring a master device within the device group. The master device is a managed PAN-OS firewall that has User-ID and group…

Submitted by rohit_dlh· Apr 18, 2026Deploy and Configure

Question

A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama. Which configuration is necessary to retrieve groups from Panorama?

Options

  • AConfigure an LDAP Server profile and enable the User-ID service on the management interface.
  • BConfigure a group mapping profile to retrieve the groups in the target template.
  • CConfigure a Data Redistribution Agent to receive IP User Mappings from User-ID agents.
  • DConfigure a master device within the device groups.

How the community answered

(21 responses)
  • A
    19% (4)
  • B
    10% (2)
  • C
    29% (6)
  • D
    43% (9)

Explanation

To use Active Directory groups in Panorama security policies, Panorama must have a way to retrieve and display those groups. This is accomplished by configuring a master device within the device group. The master device is a managed PAN-OS firewall that has User-ID and group mapping already configured and communicating with Active Directory. Panorama queries this master device to pull the list of available AD groups for use in policy. LDAP Server Profiles (A) and group mapping (B) are configured on the individual firewalls or in templates, but the Panorama device group still needs a master device designated to supply group data. A Data Redistribution Agent (C) deals with IP-to-user mappings, not group retrieval for policy creation.

Topics

#Active Directory Integration#Panorama Management#User-ID#Device Groups

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice