02-19-2003 07:06 AM - edited 03-10-2019 07:09 AM
Is it possible to do Authorization only in the ACS for windows 3.1 using the Acive Directory user database without defining the users manually in the ACS?
02-19-2003 01:01 PM
Yes you can, all you have to do is create a group in ACS, create a group in AD. Then you go into ACS/External User Databases/Databse Group Mappings and map the two groups together. Then all you have to do is add the user to the AD group. Here is a link to that section of the manual.
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs31/acsuser/q.htm
02-20-2003 06:09 AM
Thank you, I will try, but I have an additional question, when you do Authentication and Authorization, everything works fine because the user is dinamically mapped (and created) to the ACS group, but when you do Authorization only, it seems as if the user is not dinamically mapped, so the Authorization fails, so is the user dinamically mapped at Authentication time? or could it be done at Authorization?
Thanks in advance
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide