11-15
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 11 Working with User Databases
Windows NT/2000 User Database
Step 4
If you are creating a configuration, follow these steps:
a.
Click Create New Configuration.
b.
Type a name for the new configuration for Windows NT/2000 authentication
in the box provided, or accept the default name in the box.
c.
Click Submit.
Result: Cisco Secure ACS lists the new configuration in the External User
Database Configuration table.
Step 5
Click Configure.
Result: The Windows NT/2000 User Database Configuration page appears.
Step 6
To restrict network access to users who have Windows dialin permission, select
the Grant dialin permission to user check box.
Note
Windows dialin permission is enabled in the Dialin section of user
properties in Windows NT and on the Dial-In tab of the user properties in
Windows 2000.
Step 7
If you want Cisco Secure ACS to authenticate explicitly using each trusted
Windows domain for usernames that are not domain-qualified, select the domains
you want Cisco Secure ACS to use to authenticate unqualified usernames in the
Available Domains list and move them to the Domain List list by clicking —>.
Note
Configuring the Domain List list is optional. For more information about
the Domain List, see
Windows Authentication, page 11-11
.
Caution
If your Domain List contains domains and your Windows SAM or Active
Directory user databases are configured to lock out users after a number of failed
attempts, users can be inadvertently locked out because Cisco Secure ACS tries
each domain in the Domain List explicitly, resulting in failed attempts for
identical usernames that reside in different domains.