Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Roles and Attributes

This thread has been viewed 9 times
  • 1.  Roles and Attributes

    Posted Sep 21, 2019 07:55 AM

    Dear Experts,

     

    When we configure active directory as authentication source, we get the options to select its field as role and/or attributes. What is meant by roles or attributes in this context?



  • 2.  RE: Roles and Attributes

    Posted Sep 21, 2019 11:29 AM
    Guess you are querying about vendor specific attributes and server derived roles.

    Where are you configuring this?
    Could you share a screen grab of it


  • 3.  RE: Roles and Attributes

    Posted Sep 21, 2019 11:31 AM
    When we configure active directory as authentication source, we get the
    options to define its fields such as department, member off etc as roles
    and attributes


  • 4.  RE: Roles and Attributes

    Posted Sep 21, 2019 11:56 AM

    This may be of help.

     

    https://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/Active%20Directory/AD_auth_source_adding.htm#Source

     

    --Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
    --Problem Solved? Click "Accepted Solution" in a post.



  • 5.  RE: Roles and Attributes

    Posted Sep 21, 2019 02:57 PM

    Let me give you an example:
    John belongs to department “Finance”, so when his laptop joins domain it belongs to the Finance group. Hopefully you AD team has done this correctly.
    In CPPM, If the Authentication Sources > Attributes > Groups enable as Role you find a role shows up automatically as “Finance” and probably another role [Machine Authenticated] in Access Tracker Summary when John laptop authenticated. You can base on this and build your Enforcement profile.
    If the Authentication Sources > Attributes > Groups enable as Attribute you find Authorization:<domain>: Groups “Finance” in Access Tracker > Input > Authorization Attributes. And of course you can build your Enforcement profile base on this.
    Hope that helps.