We recommend using
a Group Include List in
the LDAP server profile, so that you can specify which groups you
want to retrieve, instead of retrieving all group information.
Allow Panorama
to use username-to-user group mapping in security policies by completing
one of the following actions:
The
Cloud Identity Engine does not auto-populate user and group information
to security policy rules and to Panorama. To simplify rule creation based
on user and group information, use a master device.
Configure one or more next-generation on-premises or VM-series
firewalls as a Master Device.