Chapter 7 Setting Up and Managing User Accounts
Advanced User Authentication Settings
7-30
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Configuring Device Management Command Authorization for a
User
Use this procedure to specify the device management command authorization set
parameters for a user. Device management command authorization sets support
the authorization of tasks in Cisco device-management applications that are
configured to use Cisco Secure ACS for authorization. You can choose one of
four options:
•
None—No authorization is performed for commands issued in the applicable
Cisco device-management application.
•
Group—For this user, the group-level command authorization set applies for
the applicable device-management application.
•
Assign a device-management application for any network device—For the
applicable device-management application, one command authorization set is
assigned, and it applies to management tasks on all network devices.
•
Assign a device-management application on a per Network Device Group
Basis—For the applicable device-management application, this option
enables you to apply command authorization sets to specific NDGs, so that it
affects all management tasks on the network devices belonging to the NDG.
Before You Begin
•
Ensure that a AAA client has been configured to use as the
security control protocol.
•
In the Advanced Options section of Interface Configuration, ensure that the
Per-user /RADIUS Attributes check box is selected.
•
In the (Cisco) section of Interface Configuration, ensure that,
under New Services, the new service corresponding to the
applicable device-management application is selected in the User column.
•
If you want to apply command authorization sets, ensure that you have
already configured one or more device management command authorization
sets. For detailed steps, see
Command Authorization Sets Configuration,
page 5-16
.