Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Changing Clearpass admin AD account

This thread has been viewed 2 times
  • 1.  Changing Clearpass admin AD account

    Posted Sep 07, 2017 09:31 AM

    Hello,

     

    I need to replace the admin account that I use for LDAP/AD access. The same account is used for the authentication sources as well as to join to the domain. The new account is a clone of the original as far as rights are concerned.

     

    I was planning on just changing the authentication sources first with the new account and then unjoin the domain and rejoin with the new account. Are there any tips or caveats in doing it this way? How about affect on users? While the domain is not joined I know the MSCHAP auths won't work. I'm doing this during a maintenance window so a minimal hit to users would be fine.



  • 2.  RE: Changing Clearpass admin AD account

    EMPLOYEE
    Posted Sep 07, 2017 09:35 AM

    Couple of comments:

    • You should not be using an administrative account for your AD authentication source, only a standard user with domain user privileges
    • The authentication source is completely independent of domain join. You can change the authentication source credentials and you don't have to re-join the domain
    • There should be no effect on users except for maybe 3-5 seconds after you change the password for the config to propogate.


  • 3.  RE: Changing Clearpass admin AD account

    Posted Sep 07, 2017 10:43 AM

    Thanks Tim. If the admin domain account that was used to join the domain is going to get removed do I need to rejoin the domain with new credentials or once joined it doesn't matter if the account gets remvoed?



  • 4.  RE: Changing Clearpass admin AD account
    Best Answer

    EMPLOYEE
    Posted Sep 07, 2017 10:53 AM

    No. The credentials used for domain join are not stored in ClearPass. They're used for the one time operation, just like joining a computer to the domain.

     

    Domain join is completely separate from the AD authentication source.



  • 5.  RE: Changing Clearpass admin AD account

    Posted Dec 20, 2018 02:17 AM

    Hi Tim,

     

    So we can also disable the same admin user after the join is finished ?