We recommend using
a Group Include List in
the LDAP server profile, so that you can specify which groups you
want to retrieve, instead of retrieving all group information.
Allow Panorama
to use username-to-user group mapping in security policies by completing
one of the following actions:
The
Cloud Identity Engine does not auto-populate user and group information
to security policy rules and to Panorama. To simplify rule creation
based on user and group information, configure a master device or
the Cloud Identity Engine and
specify it during your Prisma Access configuration.