
Chapter 11 Working with User Databases
Windows NT/2000 User Database
11-8
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
What’s Supported with Windows NT/2000 User Databases
Cisco Secure ACS supports the use of Windows external user databases for the
following features:
•
Authentication—Cisco Secure ACS supports ASCII, PAP, MS-CHAP
(versions 1 and 2), LEAP, and PEAP(EAP-GTC) authentication with
Windows NT 4.0 Security Accounts Manager (SAM) database or a Windows
2000 Active Directory database. Cisco Secure ACS also supports EAP-TLS
authentication with a Windows 2000 Active Directory database. Other
authentication protocols are not supported with Windows NT/2000 external
user databases.
Note
Authentication protocols not supported with Windows NT/2000
external user databases may be supported by a different external user
database. For more information about authentication protocols and
the external database types that support them, see
Authentication
Protocol-Database Compatibility, page 1-9
.
•
Group Mapping for Unknown Users—Cisco Secure ACS supports group
mapping for unknown users by requesting group membership information
from Windows user databases. For more information about group mapping
for users authenticated with a Windows user database, see
Group Mapping by
Group Set Membership, page 12-14
.
•
Password-Aging—Cisco Secure ACS supports password aging for users
authenticated by a Windows user database. For more information, see
User-Changeable Passwords with Windows NT/2000 User Databases,
page 11-13
.
•
Dial-in Permissions—Cisco Secure ACS supports use of dial-in permissions
from Windows user databases. For more information, see
Preparing Users for
Authenticating with Windows NT/2000, page 11-14
.
•
Callback Settings—Cisco Secure ACS supports use of callback settings
from Windows user databases. For information about configuring
Cisco Secure ACS to use Windows callback settings, see
Setting User
Callback Option, page 7-10
.