<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS AD authentication with alias in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290131#M565425</link>
    <description>&lt;P&gt;Hello community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently preparing a migration from ACS to ISE 3.0. We use ACS as TACACS service for all our switches and we have local user accounts. Because of security recommendations I'd like to move away from local accounts to AD authentication. However, our AD accounts are some random numbers and all our device admins are used to authenticate with a very simple 2-letter acronym of their name. We cannot make any changes to AD as this is managed by a whole other team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question thus is, can we somehow map an alias to an AD-account name in ISE? For example, a device admin named Steve Johnson, logs in with credential SJ, but his AD account is T1598863.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 14:24:54 GMT</pubDate>
    <dc:creator>daan.celie</dc:creator>
    <dc:date>2021-02-11T14:24:54Z</dc:date>
    <item>
      <title>TACACS AD authentication with alias</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290131#M565425</link>
      <description>&lt;P&gt;Hello community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently preparing a migration from ACS to ISE 3.0. We use ACS as TACACS service for all our switches and we have local user accounts. Because of security recommendations I'd like to move away from local accounts to AD authentication. However, our AD accounts are some random numbers and all our device admins are used to authenticate with a very simple 2-letter acronym of their name. We cannot make any changes to AD as this is managed by a whole other team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question thus is, can we somehow map an alias to an AD-account name in ISE? For example, a device admin named Steve Johnson, logs in with credential SJ, but his AD account is T1598863.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290131#M565425</guid>
      <dc:creator>daan.celie</dc:creator>
      <dc:date>2021-02-11T14:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS AD authentication with alias</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290191#M565430</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;U&gt;&lt;EM&gt;&amp;gt;I'd like to move away from local accounts to AD authentication&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;In case of network lockups it may be desirable to keep a local account available too on a switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;U&gt;&lt;EM&gt; &amp;nbsp; &amp;gt;can we somehow map an alias to an AD-account name in ISE&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I doubt this can be done, but even it could. Remember ISE is a corner-stone of your Intranet security environment. Good integration or communication with the AD-admin group is therefore strongly recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290191#M565430</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-02-11T15:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS AD authentication with alias</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290930#M565449</link>
      <description>&lt;P&gt;Not really what it's meant for but I used identity rewrite to achieve this. It's only 10 people or so that manage the switches on a daily basis so it's manageable with identity rewrite.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 18:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ad-authentication-with-alias/m-p/4290930#M565449</guid>
      <dc:creator>daan.celie</dc:creator>
      <dc:date>2021-02-12T18:07:32Z</dc:date>
    </item>
  </channel>
</rss>

