User data

This reference describes how user records are created and updated in the database and what identity-related information the system stores.

When an identity source reports a user login for a user who is not already in the database, the user is added to the database, unless you have specifically restricted that login type.

The system updates the users database when one of the following occurs:

  • A user on the Cloud-Delivered Firewall Management Center manually deletes a non-authoritative user from the Users table.

  • An identity source reports a logoff by that user.

  • A realm ends the user session as specified by the realm's User Session Timeout: Authenticated Users, User Session Timeout: Failed Authentication Users, or User Session Timeout: Guest Users setting.

Note

If you have ISE/ISE-PIC configured, you may see host data in the users table. Because host detection by ISE/ISE-PIC is not fully supported, you cannot perform user control using ISE-reported host data.

The type of user login that the system detected determines what information is stored about the new user.

Identity Source

Login Type

User Data Stored

ISE/ISE-PIC

Active Directory

LDAP

RADIUS

RSA

  • username

  • current IP address

  • Security Group Tag (SGT) — not supported with ISE-PIC

  • endpoint profile/device type — not supported with ISE-PIC

  • endpoint location/location IP — not supported with ISE-PIC

  • type (LDAP)

TS Agent

Active Directory

  • username

  • current IP address

  • start port

  • end port

  • type (LDAP)

captive portal

Active Directory

LDAP

  • username

  • current IP address

  • type (LDAP)

traffic-based detection

LDAP

AIM


Oracle

SIP

HTTP

FTP

MDNS

  • username

  • current IP address

  • type (AD)

POP3

IMAP

  • username

  • current IP address

  • email address

  • type ( pop3 or imap )

Note

No data about Microsoft Azure Active Directory users is displayed in this table.

If you configure a realm to automatically download users, the Cloud-Delivered Firewall Management Center queries the servers based on the interval you specified. It may take five to ten minutes for the Cloud-Delivered Firewall Management Center database to update with user metadata after the system detects a new user login. The Cloud-Delivered Firewall Management Center obtains the following information and metadata about each user:

  • username

  • first and last names

  • email address

  • department

  • telephone number

  • current IP address

  • Security Group Tag (SGT), if available

  • endpoint profile, if available

  • endpoint location, if available

  • start port, if available

  • end port, if available

The number of users the Cloud-Delivered Firewall Management Center can store in its database depends on your Cloud-Delivered Firewall Management Center model. When a non-authoritative user login is detected on a host, that login is recorded in the user and host history. If no authoritative user is associated with the host, a non-authoritative user can be the current user for the host. However, after an authoritative user login is detected for that host, only another authoritative user login changes the current user.

Note that traffic-based detection of AIM, Oracle, and SIP logins create duplicate user records because they are not associated with any of the user metadata that the system obtains from LDAP servers. To prevent overuse of user count because of duplicate user records from these protocols, configure traffic-based detection to ignore those protocols.

You can search, view, and delete users from the database; you can also purge all users from the database.

For information about general user-related event troubleshooting, refer to Troubleshoot realms and user downloads .