<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS and Microsoft AD in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520889#M34649</link>
    <description>&lt;P&gt;I wanted to know if Cisco ACS in any way extends the Microsoft Active Directory schema. I'm thinking not but co-workers want some sort of comfirmation. It's simply an authentication request that either gets accepted or rejected right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the input!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Andrew Hanson&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 18:47:03 GMT</pubDate>
    <dc:creator>Andrew.Hanson</dc:creator>
    <dc:date>2021-07-04T18:47:03Z</dc:date>
    <item>
      <title>ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520889#M34649</link>
      <description>&lt;P&gt;I wanted to know if Cisco ACS in any way extends the Microsoft Active Directory schema. I'm thinking not but co-workers want some sort of comfirmation. It's simply an authentication request that either gets accepted or rejected right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the input!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Andrew Hanson&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 18:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520889#M34649</guid>
      <dc:creator>Andrew.Hanson</dc:creator>
      <dc:date>2021-07-04T18:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520890#M34650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco ACS server will work with AD. You should not have any problem with this setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2006 22:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520890#M34650</guid>
      <dc:creator>b.hsu</dc:creator>
      <dc:date>2006-03-21T22:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520891#M34651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are right, ACS doesn´t extend MS AD in anyway. It only use AD to authenticate users, but ACS doesn´t have to do with MS AD for other reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This apply for both ACS Appliance and ACS over MS Windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2006 04:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520891#M34651</guid>
      <dc:creator>fbellom</dc:creator>
      <dc:date>2006-03-23T04:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520892#M34653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks all for the clarification!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2006 16:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520892#M34653</guid>
      <dc:creator>Andrew.Hanson</dc:creator>
      <dc:date>2006-03-23T16:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520893#M34654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS doesn't extend AD per se, but ACS does permit other options and functional extension . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, with AD, your auth options are PEAP and EAP-TLS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ACS, you get PEAP and EAP-TLS, but you also get LEAP and EAP-FAST ... which you may need for fast secure roaming. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are others for both (common to both, i.e., MAC filtering) but I believe these would be the most common and desirable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS also provides TACACS+, which can be handy for pushing parameters down to the client, applying scopes and other non-RADIUS functionality. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWIW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2006 21:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520893#M34654</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-03-23T21:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520894#M34657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the post Scott. However, AD isn't a RADIUS solution like ACS (or IAS) right? What you're really talking about is EAP methods that are supported, not neccessarily schema modifications within AD? So ACS does not NEED to create AD objects that are populated with attributes/properties that are integral to the EAP authentication method. I think thats right but please let me know if its not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2006 00:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520894#M34657</guid>
      <dc:creator>Andrew.Hanson</dc:creator>
      <dc:date>2006-03-24T00:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Microsoft AD</title>
      <link>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520895#M34658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The combination of AD and IAS can provide some compatible auth methods. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS, either stand-alone or using the AD as an auth source can provide pretty much all of the available methods. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS doesn't need anything from the AD aside from the username / password for a MS-CHAP-v2 (usually inside an EAP system) and / or possibly MAC, maybe certificate info (the cert would usually go into the ACS software, even if it's running on the AD or the CA ...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, ACS hands the username/password to the AD, asks" Is this one of yours?", .... if the AD responds affirmatively, then ACS / RADIUS sends the "OK to pass" and opens up the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Being that AD is LDAP-based, it's likely that you can, if you want, add other attributes to pass along to ACS, but it's not necessary. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2006 18:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-and-microsoft-ad/m-p/520895#M34658</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-03-24T18:58:30Z</dc:date>
    </item>
  </channel>
</rss>

