Check and Refresh Palo Alto User-ID Group Mapping

  • SSH Into the Device and run the following command
show user group list
  • The output below indicates group mapping is not functional
Total: 0
* : Custom Group
  • Run the following command to refresh group mappings
debug user-id refresh group-mapping all
debug user-id refresh group-mapping xmlapi-groups
  • Rerun show user group list to verify groups have been picked up