Chapter 11 Working with User Databases
Windows NT/2000 User Database
11-14
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Preparing Users for Authenticating with Windows NT/2000
Before using the Windows NT/2000 user database for authentication, follow these
steps:
Step 1
Make sure the username exists in the Windows NT/2000 user database.
Step 2
In the Windows NT User Manager or in Windows 2000 Active Directory Users
and Computers, clear the following User Properties check boxes:
•
User must change password at next logon
•
Account disabled
Step 3
If you want to control dial-in access from within Windows NT, click Dial-in and
select Grant dialin permission to user. In Windows 2000, access the User
Properties dialog box, select the Dial-In tab, and in the Remote Access area, click
Allow access. You must also configure the option to reference this feature under
Database Group Mappings in the External User Databases section of
Cisco Secure ACS.
Configuring a Windows NT/2000 External User Database
To configure Cisco Secure ACS to authenticate users against the Windows
NT/2000 user database in the trusted domains of your network, follow these steps:
Step 1
In the navigation bar, click External User Databases.
Step 2
Click Database Configuration.
Result: Cisco Secure ACS displays a list of all possible external user database
types.
Step 3
Click Windows NT/2000.
Result: If no Windows NT/2000 database configuration exists, the Database
Configuration Creation table appears. Otherwise, the External User Database
Configuration page appears.