<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One User - Multiple Groups - ACS4.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209271#M115651</link>
    <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that one of the AD user who is already a member of multiple groups in AD, can work in the same way with ACS 4.2? Actually, my client has created multiple groups on AD like IT-Group, Corp-Group and VIP-Group, and these groups are mapped on ACS. Now we are authenticating the users with corresponding SSID over Wireless network by creating NAR with which matches DNIS (SSIDs are same as AD Groups). Some of the users are member of all 3 or 2 groups, but we have observed the user who is member of 2 or more groups is always authenticated with the 1 group that is on ACS. Is it the limitation of ACS4.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:34:54 GMT</pubDate>
    <dc:creator>Sohail Muhammad</dc:creator>
    <dc:date>2019-03-11T03:34:54Z</dc:date>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209271#M115651</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that one of the AD user who is already a member of multiple groups in AD, can work in the same way with ACS 4.2? Actually, my client has created multiple groups on AD like IT-Group, Corp-Group and VIP-Group, and these groups are mapped on ACS. Now we are authenticating the users with corresponding SSID over Wireless network by creating NAR with which matches DNIS (SSIDs are same as AD Groups). Some of the users are member of all 3 or 2 groups, but we have observed the user who is member of 2 or more groups is always authenticated with the 1 group that is on ACS. Is it the limitation of ACS4.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209271#M115651</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2019-03-11T03:34:54Z</dc:date>
    </item>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209272#M115652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is any way to achieve this task. You can say this is limitation of ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jun 2013 08:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209272#M115652</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-30T08:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209273#M115653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS always maps users to a single ACS group; yet a user can belong to more than one group set mapping.&lt;SPAN style="color: #0000ff;"&gt; When you configure an ACS group mapping based on group set membership, you can add one or many external user database groups to the set.&lt;STRONG&gt; For ACS to map a user to the specified ACS group, the user must match all external user database groups in the set.&lt;/STRONG&gt; &lt;/SPAN&gt;It actually work as a AND operator so if user satisfy the condition, it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS prevents conflicting group set mappings by assigning a mapping order to the group set mappings. When a user who is authenticated by an external user database is assigned to an ACS group, ACS starts at the top of the list of group mappings for that database. ACS sequentially checks the user group memberships in the external user database against each group mapping in the list. When finding the first group set mapping that matches the external user database group memberships of the user, ACS assigns the user to the ACS group of that group mapping and terminates the mapping process. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group-Mapping with ACS 4.2&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940485" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jun 2013 12:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209273#M115653</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-30T12:28:46Z</dc:date>
    </item>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209274#M115655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group mapping on ACS maps the user to one and only one group. So, a specific user can be only a member of one ACS group at any specific time.&lt;/P&gt;&lt;P&gt;If you are using group mapping to map the groups from external DB (AD) then the mapping goes sequentially as described by Jatin above. The first match assigns the group.&lt;/P&gt;&lt;P&gt;So, if a user is a member of both AD groups Corp and VIP, it will be mapped to the first one appears in the group mapping configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want the mapping to always work you better make users part of specific group amont the three that you use or to prioterize the order of the mapping which satisfies your requirement. i.e. if a user part of all gropus and you want that one to be a part of VIP only in this case, put the VIP group mapping configuration first followed by other group mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 08:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209274#M115655</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-07-01T08:11:59Z</dc:date>
    </item>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209275#M115657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So does ACS 5.x version have some flexibility to achieve this goal? With Rule-Based Policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 05:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209275#M115657</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2013-07-06T05:59:44Z</dc:date>
    </item>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209276#M115659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, with ACS 5.x you do have this flexibility ane what you're thinking can be done. With ACS 5.x &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can select active directory group under customize page in which you choose the types of&amp;nbsp; conditions to use in policy rules. A new Conditions column appears in&amp;nbsp; the Policy page for each condition that you add.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can select AD1:ExternalGroup and there you have 2 options Contains Any or All. This work like OR / AND operator that you can select based on your requirement.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/access_policies.html#wp1064976"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/user/guide/access_policies.html#wp1064976&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 11:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209276#M115659</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-06T11:07:51Z</dc:date>
    </item>
    <item>
      <title>One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209277#M115661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jatin for your reply. But I just got a reply from Cisco TAC engineer that the same can be done on ACS 4.2 with configuring Group Set for external Database groups. I tried to find out the configuration method but only manage to find the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940457"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940457&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you guide me how to configure Group Set?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 13:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209277#M115661</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2013-07-06T13:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209278#M115662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please understand this example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, a user named Mary is assigned to the three-group combination of &lt;STRONG&gt;Engineering&lt;/STRONG&gt;,&lt;STRONG&gt; Marketing&lt;/STRONG&gt;, and &lt;STRONG&gt;Managers&lt;/STRONG&gt;. Mary should be granted the privileges of a &lt;STRONG&gt;manager&lt;/STRONG&gt; rather than an engineer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- &lt;SPAN style="color: #ff0000;"&gt;Mapping A assigns to ACS Group 2 users who belong to all three groups of which Mary is a member. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-&lt;SPAN style="color: #0000ff;"&gt; Mapping B assigns to ACS Group 1 users who belong to the Engineering and Marketing groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- &lt;SPAN style="color: #339966;"&gt;Mapping C assigns to ACS Group 3 users who belong to the Engineering Group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;STRONG style="color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS GROUP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD EXTERNAL GROUP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;A.&amp;nbsp;&amp;nbsp;&amp;nbsp; Group 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engineering, Marketing and Managers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;B.&amp;nbsp;&amp;nbsp; Group 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engineering, Marketing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;&lt;STRONG&gt;C.&amp;nbsp;&amp;nbsp; Group 3&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engineering&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- If Mapping B is listed first, ACS authenticates Mary as a user of Group 1 and she is be assigned to Group 1, rather than Group 2 as managers should be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- A user must match all the groups in the Selected list so that ACS can use this group set mapping to map the user to an ACS group; however, a user can also belong to other groups (in addition to the groups listed) and still be mapped to an ACS group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Order of group mapping is very important.&lt;/P&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, please let me know if you've some other requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 14:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209278#M115662</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-06T14:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: One User - Multiple Groups - ACS4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209279#M115663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you've asked the same question in different section. let's troubleshoot on a single post, that would avoid confusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 14:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-user-multiple-groups-acs4-2/m-p/2209279#M115663</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-06T14:32:27Z</dc:date>
    </item>
  </channel>
</rss>

