Chapter 6 Setting Up and Managing User Groups
User Group Setup Features and Functions
6-2
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
•
Configuration-specific User Group Settings, page 6-15
—This section
details procedures that you would perform only as applicable to your
particular network security configuration.
•
Group Setting Management, page 6-51
—This section includes basic
administrative procedures, such as determining the users in a group or
renaming a group.
User Group Setup Features and Functions
The Group Setup section of the Cisco Secure ACS HTML interface is the
centralized location for operations regarding user group configuration and
administration. For information about network device groups (NDGs), see
Network Device Group Configuration, page 4-27
.
Default Group
If you have not configured group mapping for an external user database,
Cisco Secure ACS assigns users who are authenticated by the Unknown User
Policy to the Default Group the first time they log in. The privileges and
restrictions for the default group are applied to first-time users. If you have
upgraded from a previous version of Cisco Secure ACS and kept your database
information, Cisco Secure ACS retains the group mappings you configured
before upgrading.
Group Settings
Cisco Secure ACS enables a full range of settings for at the group
level. If a AAA client has been configured to use as the security
control protocol, you can configure standard service protocols, including PPP IP,
PPP LCP, ARAP, SLIP, and Shell (exec), to be applied for the authorization of
each user who belongs to a particular group.
Note
You can also configure settings at the individual user level. User-level
settings always override group level settings.