cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2717
Views
10
Helpful
4
Replies

Radius authentication allow some of AD accounts not all of them

CSCO12780120
Level 1
Level 1

Hi everyone,

 

Can I use Radius authentication but allow parts of AD accounts to login device?

Or only few of user can access privilege level 15?

 

Configuration :

aaa authentication login default group radius local
aaa authentication enable default none
aaa authorization exec default if-authenticated
aaa accounting exec default stop-only group radius

 

Looking forward to your response guys.

 

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni
If you use ISE, your Authorization policy could be to allow users from a certain AD groups (say Admins) to access network devices. Even though it authenticates all users on AD, the Authorization can restrict users based on your requirements.

View solution in original post

4 Replies 4

Rahul Govindan
VIP Alumni
VIP Alumni
If you use ISE, your Authorization policy could be to allow users from a certain AD groups (say Admins) to access network devices. Even though it authenticates all users on AD, the Authorization can restrict users based on your requirements.

jeremykolkosn
Level 1
Level 1

Is there an updated document for configuring Radius with Microsoft Network Policy Server (NPS), which replaced ISE?

 

No, NPS has not replaced ISE. (-:

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: