07-16-2012 05:55 AM
Hi
I'm finding it hard to create groups in AD and have the diffrent groups in AD assigned to diffrent roles in Cisco LMS 4.1
Is it possible to have diffrent AD groups to assign the diffrent roles in LMS? If it's possible how should I do it so it work as painless as possible?
07-16-2012 06:11 AM
CiscoWorks LMS will use PAM (Pluggable Authentication Module), like TACACS+, Radius, Kerberos, MSAD etc, only for authentication part. The role/privilege or Authorization would be local.
What authorization priv a user would has to be configured locally on LMS, which you can do from :
Admin > System > User Management > Local User Setup.
For more details, please check :
-Thanks
Vinod
07-17-2012 02:40 AM
I found the following in the document: "The LMS Server determines user roles. Therefore, all users must be in the local database of user IDs and passwords. Users who are authenticated by an alternative service and who are not in the local database are assigned to the same role as the guest user (by default, the Help Desk role)."
So if I have one AD group that I want to assign a Super Admin role, another I want to have Network Administrator role and the third a helpdesk role. That isn't possible from what I can read in the text above. Is there any other way I can manage what I want to do?
07-26-2012 12:59 AM
All the roles will be defined in LMS itself now. For those whom you want to give just help desk priveldge/role, no need to define them in LMS locally.
Example, say there are three users A,B and C, you want to give a help Desk, Admin and Super Admin role.
AD LMS
A
B
C
-Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide