04-25-2012 10:23 PM - edited 03-10-2019 07:02 PM
Hi Expert,
I have some question about user ACS for query AD. User-id that ACS use for query AD have to be unlock and never expire use-id ? If user-id is locked, ACS still can query as normally? Thank you for sharing.
04-26-2012 09:53 PM
No the account that connects to ACS to AD is only there to join the domain (create the computer account) if the account is locked it will still be able to authenticate users successfully. However, if the services are ever disrupted or the AD configuration is removed and then re-added then the ability to join the domain will fail.
thanks,
Tarik Admani
04-27-2012 01:56 AM
Hi Tarik Admani,
Many thanks for reply. This information don't depend on ACS version, correct? I current use ACS 4.2
04-27-2012 04:01 PM
Wow, i should have caught that and assumed this was for 5.x. So ACS 4.2 operates differently, it has to be installed on a machine that is joined to your domain. ACS for windows has to run on a server that is a part of your domain or the remote agent has to run to on a machine that is a member of your domain, once the machine is joined to the domain then it should work fine. If you delete the account from AD or you decide to leave the domain through the workstation itself then you will have to provide the domain admin credentials again in order to join one more time.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide