cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2528
Views
0
Helpful
3
Replies

ISE 3.0 Internal User Accounts for TACACS+ - Have different password policy for different user accounts possible?

wags
Level 1
Level 1

Based on this old post/answer this was not possible 3 years ago.  Is that still true today with ISE 3.0?

 

Paraphrase old post:

Is it possible to have an internal user account (for TACACS+ user) never expire AND to have the Users Password Policies in effect for all other users (password expiration, account lockout durations, etc.)?   Looking to have a service account that never expires and still use the password policies for the rest.

 

Answer was:

You have the option of modifying the User and Password policies globally for internal users but not per user.

 

Original link:

https://community.cisco.com/t5/network-access-control/ise-internal-user-account-never-expire/td-p/3424738

 

TIA

1 Accepted Solution

Accepted Solutions

Hi @wags ,

 please take a look at: CSCvu07107 ENH ISE Password Policy for Internal User per User/Group.

"...

Symptom:
Right now there is one password policy for all internal user groups. ISE could use password policies for multiple internal user per user/group instead of just one global policy.

Workaround:
none

Last Modified: May 3,2021
Status: Open
Severity: 6 Enhancement

..."

 

Hope this helps !!!

View solution in original post

3 Replies 3

Hi @wags ,

 please take a look at: CSCvu07107 ENH ISE Password Policy for Internal User per User/Group.

"...

Symptom:
Right now there is one password policy for all internal user groups. ISE could use password policies for multiple internal user per user/group instead of just one global policy.

Workaround:
none

Last Modified: May 3,2021
Status: Open
Severity: 6 Enhancement

..."

 

Hope this helps !!!

wags
Level 1
Level 1

Seems like a given that you would have the ability to assign different policies to different "objects".  Guess maybe the product team think everything should go to an external security entity for that flexability.