<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 3.0(2) - Authenticating users from Active Directory and NT4 Domains in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-0-2-authenticating-users-from-active-directory-and-nt4/m-p/189819#M439165</link>
    <description>&lt;P&gt;We are running ACS 3.02 on an Active Directory Domain Controller.  Most users are still in NT4 but some are migrated to AD (SIDHistory migration) and as such have their NT4 account of the same name, disabled.   ACS has both domains configured in the domain list.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem: &lt;/P&gt;&lt;P&gt;User accounts in AD get locked out after one bad password when authenticating against a NAS -- the domain policies are three attempts.  This happens when the NT account of the same name is disabled.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears like ACS looks at both domains, finds the same user name in the NT domain (which is disabled intentionally) and then locks out the AD account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interestingly, if the User account in NT is "expired" this does not happen.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g.&lt;/P&gt;&lt;P&gt;AD domain - "Domain A" and "User A" - everything is enabled&lt;/P&gt;&lt;P&gt;NT domain - "Domain B" and "User A" - the user account is disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User A attempts auth against a NAS, and supplies the wrong password only once.  User A in Domain A then gets locked out.  If User A in Domain B is not disabled, the one bad password attempt does not lock out User A in Domain A.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:22:25 GMT</pubDate>
    <dc:creator>rdone-burcea</dc:creator>
    <dc:date>2019-03-10T14:22:25Z</dc:date>
    <item>
      <title>ACS 3.0(2) - Authenticating users from Active Directory and NT4 Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-0-2-authenticating-users-from-active-directory-and-nt4/m-p/189819#M439165</link>
      <description>&lt;P&gt;We are running ACS 3.02 on an Active Directory Domain Controller.  Most users are still in NT4 but some are migrated to AD (SIDHistory migration) and as such have their NT4 account of the same name, disabled.   ACS has both domains configured in the domain list.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem: &lt;/P&gt;&lt;P&gt;User accounts in AD get locked out after one bad password when authenticating against a NAS -- the domain policies are three attempts.  This happens when the NT account of the same name is disabled.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears like ACS looks at both domains, finds the same user name in the NT domain (which is disabled intentionally) and then locks out the AD account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interestingly, if the User account in NT is "expired" this does not happen.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g.&lt;/P&gt;&lt;P&gt;AD domain - "Domain A" and "User A" - everything is enabled&lt;/P&gt;&lt;P&gt;NT domain - "Domain B" and "User A" - the user account is disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User A attempts auth against a NAS, and supplies the wrong password only once.  User A in Domain A then gets locked out.  If User A in Domain B is not disabled, the one bad password attempt does not lock out User A in Domain A.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-0-2-authenticating-users-from-active-directory-and-nt4/m-p/189819#M439165</guid>
      <dc:creator>rdone-burcea</dc:creator>
      <dc:date>2019-03-10T14:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.0(2) - Authenticating users from Active Directory and</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-0-2-authenticating-users-from-active-directory-and-nt4/m-p/189820#M439166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are seeing is expected behavior on the version of ACS you are running.  Your interpretation is quite accurate that it searches all the domain if you provide the wrong password until it finds the user succeeds.  You may try to send the domain_name\user_name and test it again with wrong password, you may not see this behavior.  If I am not completely off, this behavior is changed in acs version 3.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2003 04:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-0-2-authenticating-users-from-active-directory-and-nt4/m-p/189820#M439166</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-07-02T04:40:31Z</dc:date>
    </item>
  </channel>
</rss>

