Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Unused guest account expiration

This thread has been viewed 1 times
  • 1.  Unused guest account expiration

    Posted Jan 08, 2016 09:54 AM

    We are implementing a self-registration option for our guests and allowing up to a six-month account.  We would like the ability to have the system automatically expire/delete the account if the user has not logged in for a period of seven days.  Is there a way this can be done?



  • 2.  RE: Unused guest account expiration

    Posted Jan 20, 2016 03:36 PM

    * bump *

    Would anyone know if this can be done?



  • 3.  RE: Unused guest account expiration

    EMPLOYEE
    Posted Jan 21, 2016 04:43 AM

    Hi Joseph,

     

    I don't think you can disable the guest account if the user hasn't logged in for 7 days.

     

    You should be able to work this around based on last login timestamp of the user. Like allow access when the account is active and the user is back within 7 days since the last login.  

     

    If you are planning to disable the account after no activity for 7 days and allow the user to re-rigester, then you can achieve the same with the above workflow by redirecting the client to registration page when you find no activity for the last 7 days.



  • 4.  RE: Unused guest account expiration

    EMPLOYEE
    Posted Jan 21, 2016 04:47 AM

    Okay, 

    I missed the actual subject "Unused guest account expiration".

     

    I don't think you can set expiry for unused guest account.



  • 5.  RE: Unused guest account expiration

    Posted Jan 21, 2016 08:28 AM

    When we provide guests an option for how long their account is valid, they are always going to choose the option with the most time.  We have found (with our current Cisco guest system), that many users create accounts, use them one time, but then are idle and in the system for up to 6 months.  We would like a way to "clean" up the accounts if we find that a user has not logged into the system for a period of seven days.



  • 6.  RE: Unused guest account expiration

    EMPLOYEE
    Posted Jan 21, 2016 09:14 AM

    CPPM will not be able to expire/delete/clean-up the guest accounts in that direction.

     

    You could try some work-around like,

    Start the guest registration with default 7days of expiration(if it works in your requirement) and keep extending the expiration by 7 days(week) if the user login before expiry. Accounts which are idel for 7 days will be expired/deleted in this way. 



  • 7.  RE: Unused guest account expiration

    Posted Jan 21, 2016 09:25 AM

    By "extending the expiration" you are referring to a manual process where either the user is able to do this on their own or a sponsor does this for them?  If that is the case then this will not work as we want an automated process.