cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5971
Views
1
Helpful
5
Replies

ISE Internal User Account - Never Expire

kkaminsk
Cisco Employee
Cisco Employee

Folks,

Is it possible to have an internal user account (for T+ users) never expire AND to have the Users Password Policies in effect for the majority of the users (password expiration and account lockout durations)?  I have a customer looking to have a few service accounts only that never expire and still use the password policies for the rest.

1 Accepted Solution

Accepted Solutions

ldanny
Cisco Employee
Cisco Employee

You have the option of modifying the User and Password policies globally for internal users but not per user.

Have a look under

Administration > Identity Management > Settings > User Authentication Settings

View solution in original post

5 Replies 5

ldanny
Cisco Employee
Cisco Employee

You have the option of modifying the User and Password policies globally for internal users but not per user.

Have a look under

Administration > Identity Management > Settings > User Authentication Settings

So the answer then is that when I am using the global policies, I cannot then do a permanent per user account.  Correct?

You are correct pretty much. For ISE internal network access users, we may globally permit users not to expire and then set expired dates on individual user accounts as needed.

Please bring your feedback to our PM team.

Is there any new development happens in new ISE releases regarding this post,

Is it possible to have an few internal user account (for Tcacas+ users) can have different password  expire AND  majority of the users  will have 90days password expiration policy ON. I have below setting on  for password rotation,  For few service account(Use in monitoring tool) we don't want to change the password so frequently or without expiry.

 
" Disable user account after |90| days if password was not changed (valid range 1 to 3650)"

In ISE 3.2 we get "Password Lifetime" option for local user

"Managing Passwords of Cisco ISE Users
From Cisco ISE Release 3.2, as an internal user of Cisco ISE, you can manage the lifetime of your Enable and Login passwords using the Password Lifetime option.
"