Consider an access rule that has only AD user names mentioned. To evaluate the traffic against this rule, the Sensor takes the source IP address in the packet and checks it against the IP-to-user mapping list that it has. This way, the Sensor determines the currently logged on user for that IP address. If this matches with any of the user names mentioned in the rule, then it is a match with respect to the source user. If not the Sensor proceeds to check the next rule.
Consider that you have mentioned only user groups in the rule. As explained above, the Sensor first determines the currently logged on user. Then it checks this user name against the user-to-user group mapping that it has. If any of the user group of this user matches with any of the user groups in the rule, it is a match with respect to source user. If not the Sensor proceeds to the next rule.
In case of both user names and user groups in the rule, the Sensor checks for the user and user group in the same order that you have configured.
How the Sensor evaluates user-based access rules
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?