__telemetryuser System Account
Focus
Focus
Next-Generation Firewall

__telemetryuser System Account

Table of Contents

__telemetryuser System Account

PAN-OS uses the permanent __telemetryuser system account to collect and upload device telemetry data securely without requiring any administrator configuration.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
For Strata Cloud Manager managed NGFWs:
  • Strata Cloud Manager Essentials
  • Strata Cloud Manager Pro
Telemetry autoenablement feature requires PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and later releases.
The __telemetryuser account is a permanent, system-generated local administrator account that PAN-OS uses to execute internal commands required for Device Telemetry data collection. You do not need to create, manage, or configure this account.
The __telemetryuser account is present on the system regardless of whether you enable or disable Device Telemetry. If you delete the account, PAN-OS recreates it during the next system reboot. To manage telemetry settings, select Tenant Management on the hub, or select SettingsTenants in Strata Cloud Manager.

Telemetry Account Visibility

You can view the __telemetryuser account in the following locations in the web interface:
  • DeviceAdministrators
  • The Logged in Admins section of the dashboard during active collection cycles
Both behaviors are expected. To protect your system security, the account cannot log in externally, execute interactive commands, or perform configuration changes.

Telemetry Account Version History

PAN-OS introduced the __telemetryuser account to permanently replace the legacy transient _cliuser account, which PAN-OS created and deleted during each collection cycle. Transitioning to a permanent account improves telemetry collection reliability.
The account is available in the following releases:
  • PAN-OS 10.2.18, PAN-OS 10.2.20, and later releases
  • PAN-OS 11.1.10-h12, PAN-OS 11.1.12, and later releases
  • PAN-OS 11.2.4-h14, PAN-OS 11.2.7-h4, PAN-OS 11.2.10, PAN-OS 11.2.11, and later releases
  • PAN-OS 12.1.4-h3, PAN-OS 12.1.5, PAN-OS 12.1.8, and later releases
  • PAN-OS 12.2.0 and later releases

Telemetry Collection Behavior

To collect telemetry data, the __telemetryuser account executes predefined, read-only command-line interface (CLI) commands and queries, compresses the output into a .tgz bundle, and uploads the bundle to the secure Palo Alto Networks® endpoint.
PAN-OS uploads bundles at the following predefined intervals:
  • Minute interval: Executes every five minutes in PAN-OS 11.0 and later releases, or every 20 minutes in releases earlier than PAN-OS 11.0.
  • Hour interval: Executes every 60 minutes.
  • Day interval: Executes every 24 hours.

Security Considerations

The __telemetryuser account incorporates the following security design controls:
  • Privileges: The account operates with limited, read-only privileges required strictly for telemetry data collection and script execution. It does not possess superuser or elevated administrative permissions.
  • Interactive access: The account does not support interactive login. You cannot use it to log in through Secure Shell (SSH), the web interface, or an application programming interface (API).
  • Configuration changes: The account is architecturally incapable of making configuration changes.
  • Disabled telemetry: The __telemetryuser account remains on the system even if you disable Device Telemetry. If you manually delete the account, PAN-OS recreates it during the next reboot to maintain consistent system behavior.

Frequently Asked Questions

  • Is __telemetryuser a security risk?
    No. The account is restricted to internal, read-only command execution. It cannot log in externally or make configuration changes.
  • Can you delete __telemetryuser?
    Do not delete the account. If you delete the account while Device Telemetry is enabled, the device sends empty bundles, which causes issues in telemetry-related services. Additionally, PAN-OS® recreates the account during the next system reboot. To stop data collection, select DeviceSetupTelemetry and disable Device Telemetry. The __telemetryuser account remains on the system regardless of your telemetry configuration.
  • Why did this account appear after a PAN-OS upgrade?
    When you upgrade to a PAN-OS® release that contains the fix for PAN-292447, the upgrade permanently adds the __telemetryuser account. In PAN-OS releases earlier than PAN-OS 10.2.18, PAN-OS 11.1.10-h12, PAN-OS 11.2.4-h14, and PAN-OS 12.1.4-h3, the legacy transient _cliuser account performed the same telemetry collection functions.
  • Why does __telemetryuser appear in Logged in Admins?
    The account appears briefly during active collection cycles. This is expected behavior and does not indicate unauthorized external access.
To learn more about Device Telemetry data categories, privacy, and encryption, see Device Telemetry Overview.