7.5 Post-Upgrade Configuration

User name matching is handled differently in PAM 3.6 compared to all the other previous versions of PAM. If the User Groups are configured for explicit direct user name matching, they will have to be updated so that the intended user's domain name is also included with user name.

For example, in PAM 3.5 if a User Group was configured so that the 'Users' field contained 'user-1', then in PAM 3.6, it should be updated to 'domain\user-1' or '*\user-1' to permit any domain context.

It is recommended that you make changes to your groups after upgrade to ensure that the users are able to see their allowed sessions in their user consoles.

For more information about this issue, see the Knowledge Base Article 7024201.