117
LDAP Authentication
To set LDAP for authentication, click the
LDAP Authentication
link. For Authentication Method, choose
either Direct Authentication or Authentication of User Attributes.
Direct Authentication
sets
authentication with the LDAP server with the user name and password entered by the user. Authentication
of User Attributes sets authentication with the LDAP server to the attributes listed on this dialog, such as
samAccountName. Unless you are very familiar with LDAP, do not add text strings to the User Name.
LDAP Group Access
LDAP server user groups can be used to control access to certain areas of the Xerox device. For
example, the LDAP server may contain a group of users called "Admin." You can configure the "Admin"
group on the device so that the members of that group will have administrator access to the device. When
a user logs in at the device with their network authentication account, the device performs an LDAP look-
up to determine if the user is a member of any groups. If the LDAP server confirms that the user is a
member of the "Admin" group, the user will have administrator access. In the System Administrator
Access Group box, enter the name of the group, defined at the LDAP server, that you want to provide with
system administrator access to the device. Repeat the process for other LDAP group access boxes.
Custom Filters
For the Email Address Filter, in the box provided, type in the LDAP search string (filter) that you wish to
apply. The filter defines a series of conditions that the LDAP search must fulfill in order to return the
information you seek. The form of the typed search string (filter) is LDAP objects placed inside
parenthesis. For example, to find all users that have an E-Mail attribute (mail enabled), type
(objectClass=user) (mail=*). If you are not familiar with LDAP search strings, use an Internet browser
search to find examples.
Configuring Network Authentication (by a Remote Accounting server)
Network authentication uses the user information managed on a remote Accounting server to manage
authentication (access) to available machine services.
Enable Network Authentication
To enable Network Authentication for use with this Device, at your networked workstation, perform the
following steps:
1.
Open your Web browser and enter the TCP/IP address of the machine in the Address or Location field.
Press
Enter
.
2.
Click the
Properties
tab.
3.
Select the
Security
folder, then the
Authentication Configuration
hot link.
4.
Select
Login to Remote Accounts
from the Login Type drop-down list, then
Network Accounting
from the Accounting Mode drop-down list.
5.
Place a checkmark in the
Enable
box for each service that you wish to restrict access to. For
explanations of each service, click the Help button.
6.
Do not place a checkmark in the
Non-account Print
box if you wish to enable people without accounts
to continue to print.
7.
From the
Verify User Details
drop-down menu, select either Yes or No (keep logon records). The
Yes selection will verify user information. When No (keep logon records) is selected, User ID and
Account ID must be entered at the Device, but user information will not be checked. A logon record
will be kept by the Device, however.
8.
If a Guest User box is available and configurable, consider whether it is advisable in your network
environment to allow simple password, guest access to this restricted service device. The default
setting is Off.
Summary of Contents for WorkCentre 7300 Series
Page 1: ...System Administrator s Guide 701P47983 WorkCentre 7300 Series ...
Page 12: ...x ...
Page 203: ......