We have CSACS 3.2(3) where users are configured with an internal SecurID account, with the unknown user policy set up to query our Windows 2000 AD for wireless users. A user might have two entries in the database: a static "matt.melbourne" RSA SecurI...