<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create a security group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643191#M55913</link>
    <description>&lt;P&gt;Create a security group called something like "ACS Users" and add the users you want access to this security group.&amp;nbsp; Users can be a part of many security groups, so it will not break anything.&amp;nbsp; Then you will select this group in your AD Groups in ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this works for you, do not forget to rate!&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2015 19:35:21 GMT</pubDate>
    <dc:creator>cybrsage</dc:creator>
    <dc:date>2015-04-23T19:35:21Z</dc:date>
    <item>
      <title>ACS end-user authentication to Active Drirectory OU</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643190#M55912</link>
      <description>&lt;P&gt;I'm running ACS 5.5.&amp;nbsp; I have end-users logging in from ASA VPN or Wireless Lan Controllers that hit ACS via RADIUS for authentication. ACS is joined to my Active Dreictory domain to actually authenticate/authorize the end-user connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works great, but I want to restrict access to users who are in a specific AD OU.&amp;nbsp; I can't use the Users and Identity Stores -&amp;gt; External Identity Stores -&amp;gt; Active Directory Groups solution because there isn't an AD group for "All users".&amp;nbsp; I can't use "Domain Users" because that includes service accounts (which are NOT in the User OU).&amp;nbsp; Service accounts are specifically what I'm trying to prohibit from VPN / Wireless access.&lt;/P&gt;&lt;P&gt;Creating an "All Users" AD group is going to be a long and somewhat painful process due to our IAM solution.&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643190#M55912</guid>
      <dc:creator>clausonna</dc:creator>
      <dc:date>2019-03-11T05:39:55Z</dc:date>
    </item>
    <item>
      <title>Create a security group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643191#M55913</link>
      <description>&lt;P&gt;Create a security group called something like "ACS Users" and add the users you want access to this security group.&amp;nbsp; Users can be a part of many security groups, so it will not break anything.&amp;nbsp; Then you will select this group in your AD Groups in ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this works for you, do not forget to rate!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 19:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643191#M55913</guid>
      <dc:creator>cybrsage</dc:creator>
      <dc:date>2015-04-23T19:35:21Z</dc:date>
    </item>
    <item>
      <title>Thank you for your fast</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643192#M55914</link>
      <description>&lt;P&gt;Thank you for your fast response - but you failed to answer my specific question.&amp;nbsp; I -know- I can create an AD group to be used by ACS for authentication.&amp;nbsp; I want/need to use just an AD OU (organizational unit).&amp;nbsp; I have 5000+ users and a fairly complex Identity Access Management solution.&amp;nbsp; Adding everyone to an "All Users" AD group is far more difficult than just having ACS restrict access based on what OU the user's account is in.&amp;nbsp; There has to be a way to do this!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 20:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643192#M55914</guid>
      <dc:creator>clausonna</dc:creator>
      <dc:date>2015-04-23T20:08:42Z</dc:date>
    </item>
    <item>
      <title>hi Clausonna,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643193#M55915</link>
      <description>&lt;P&gt;hi &lt;G class="gr_ gr_20 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="20" data-gr-id="20"&gt;Clausonna&lt;/G&gt;,&lt;/P&gt;
&lt;P&gt;I am looking for similar solution. are you able to find something for yourself ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 13:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643193#M55915</guid>
      <dc:creator>Atta ullah Meer</dc:creator>
      <dc:date>2017-03-30T13:33:54Z</dc:date>
    </item>
    <item>
      <title>AFAIK, you have to use</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643194#M55916</link>
      <description>&lt;P&gt;AFAIK, you have to use security groups.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 19:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-end-user-authentication-to-active-drirectory-ou/m-p/2643194#M55916</guid>
      <dc:creator>cybrsage</dc:creator>
      <dc:date>2017-03-30T19:03:53Z</dc:date>
    </item>
  </channel>
</rss>

