Configuring Windows Authentication And Authorization - McAfee EPOLICY ORCHESTRATOR 4.5 Product Manual

Hide thumbs Also See for EPOLICY ORCHESTRATOR 4.5:
Table of Contents

Advertisement

Configuring ePolicy Orchestrator
Managing ePolicy Orchestrator users with Active Directory
The user account used to register the LDAP server with ePolicy Orchestrator must be trusted
via a bi-directional transitive trust, or must physically exist on the domain where the LDAP
server belongs.
Windows authorization
The server setting for Windows authorization specifies which Active Directory (AD) server ePolicy
Orchestrator uses to gather user and group information for a particular domain. You can specify
multiple domain controllers and AD servers. this server setting supports the ability to dynamically
assign permission sets to users that supply Windows credentials at login.
NOTE:
ePolicy Orchestrator can dynamically assign permission sets Windows Authenticated
users even if user autocreation is not enabled.
Assign permissions
You must assign at least one permission set to an AD group other than a user's Primary Group.
Dynamically assigning permission sets to a user's Primary Group is not supported, and results
in application of only those permissions manually assigned to the individual user.
User autocreation
When you have configured the previously discussed sections, you can enable the User
autocreation server setting. User autocreation allows user records to be automatically created
when the following conditions are met:
• Users provide valid credentials, using the <domain\name> format. For example, a user with
Windows credentials jsmith1, who is a member of the Windows domain named eng, would
supply the following credentials: eng\jsmith1, along with the appropriate password.
• The domain used in the logon attempt maps to a domain listed in the windows authorization
server setting.
• The Active Directory server mapped to the domain contains a record for the user.
• The user is a member of at least one group that maps to an ePO permission set.

Configuring Windows authentication and authorization

Use these tasks to set up automatic user creation.
Tasks
Configuring Windows authentication
Registering LDAP servers
Configuring Windows authorization
Enabling user autocreation
Configuring Windows authentication
Use this task to configure Windows authentication. How you configure these settings depends
on several variables:
• Do you want to use a WINS server to look up which domain your users are authenticating
against?
• Do you want to use multiple domain controllers?
McAfee ePolicy Orchestrator 4.5 Product Guide
37

Advertisement

Table of Contents
loading

Table of Contents