CISCOWORKS LMS and CISCOSECURE ACS Authenticate any user with HD role

Hi:
We are using CiscoSecure for authentication and authorization for differente apps.
Specifically, any user already in the ACS database is authenticated to log in CiscoWorks LMS, with HD role (this happens although none of the CiscoWorks apps have been checked for this group). 
Why is this happening?
We don´t want that any user (although they are only permitted the HD role) could login.
Thanks a lot
Julio

Follow the ACS integration guide to ensure the group you don't want to have access to LMS have the roles set to "NONE" instead of the default HD roles.
http://www.cisco.com/en/US/partner/prod/collateral/netmgtsw/ps6504/ps6528/ps2425/prod_white_paper0900aecd80613f62.html

Similar Messages

  • I am going to buy unlocked iphone 5.. i will be going to india nxt months and will stay there for a while... so my question is will i get warrenty in india.. and will there be any problem with using indian sims..?? thnx for the help..

    i am going to buy unlocked iphone 5.. i will be going to india nxt months and will stay there for a while... so my question is will i get warrenty in india.. and will there be any problem with using indian sims..?? thnx for the help..

    The warranty for the iPhone is not and has never been International.
    Warranty and support are ONLY valid in the country of origin.  The only exception is the EU where the entire EU is treated as one country.
    If the device will be used in India, buy it in India.
    An unlocked iPhone will work on any supported GSM carrier world wide.  The LTE portion of a US purchased, unlocked iPhone is unlikely to work outside North America as it does not support the appropriate bands used in other countries.

  • How do I get connected to a server on my network via an IP address?  When I try to open in a URL and login as a registered user with proper login it errors out saying there was a problem with connecting to the server?

    I am new to Mac...How do I get connected to a server on my network via a hyper link IP address path?  When I try to open in a URL and login as a registered user with proper login it errors out saying there was a problem with connecting to the server?

    Some of the following is going to use some technical terms — this area is inherently somewhat technical. 
    If you don't understand some part of the following reply, please ask.
    Is this your own OS X Server system on your own network, or is this some other server within some larger organization? 
    You're posting this in the OS X Server forum, which is a software package that allows OS X systems to provide web-based and many other services; to become servers.
    If it's your OS X Server on your network, then the network and DNS configurations are suspect, or the server is somehow malfunctioning or misconfigured.   This is unfortunately fairly common, as some folks do try to avoid setting up DNS services.
    If it's a larger organization and somebody else is managing the server and the network, then you'll probably need to contact the IT folks for assistance; to learn the network setup and DNS requirements, and if there's a problem with the server itself.
    The basic web URL "hyper link IP address path" — without using DNS — usually looks something the following, where you'll need to replace 10.20.30.40 with the IP address of your server:
    http://10.20.30.40
    UptimeJeff has posted a URL that specifies the AFP file system; an OS X file share.  That's used if you're connecting to an Apple storage service somewhere on your network.  You might alternatively need to specify smb://10.20.30.40 or such, if it's a Windows file server.  (There can be additional requirements for connecting to Windows Server systems, too.)
    If there's local IT staff available here, please contact them for assistance.  If these are your own local systems and your own local OS X Server system, then some information on the server will be needed.  (If you're on a NAT'd network, you'll also need to get DNS services configured and working on your local OS X Server system and your network — you'll not be able to skip this step and reference ISP DNS servers here — or things can and usually will get weird.)

  • My iPad 2 won't receive text messages and is not sharing any data with my iPhone 4. Please help!

    My iPad 2 won't receive text messages and is not sharing any data with my iPhone 4. Please help!

    The iPad receives Text Messages through Apple's iMessage feature. Make sure this is turned on on your phone. Also, text messages received at your phone number are not shared with the iPad. Make sure that iMessage texts are being sent to your EMAIL ADDRESS

  • Until now, I have used Bridge and PS, and when I enter any map with Bridge, it shows me thumb nails

    Until now, I have used Bridge and PS, and when I enter any map with Bridge, it shows me thumb nails of all the pictures in this map. CAn't I do that with PS Elements 11??

    contact adobe support by clicking 'still need help' as soon as available, https://helpx.adobe.com/contact.html

  • I can't purchase on my candy crush game and there isn't any problems with my account.

    I periodically can't purchase on candy crush and there isn't any problems with my account. Help!

    Open current iTunes on your computer. Connect iPhone to the computer with USB Cable. Follow directions or click the Restore button of iTunes.

  • Performance tab not working in Enterprise Manager for user with dba role

    Database: 11g2
    New to Oracle. Don't want share SYS user account among dbas. Tried to create user with dba role to perform all tasks.
    1. Removed DBMS_JOB, DBMS_LOB, UTL_FILE, UTL_HTTP, UTL_SMTP, and UTL_TCP from PUBLIC
    2. Created user dbauser1 with dba role
    3. Log in as dbauser1 in Enterprise Manager
    After click Performance tab, it just went straight to "Database Login" page. No error message.
    Any suggestions or advice will be appreciated.
    piaoma

    Hi Gourav,
    This is the wsdl url:
    http://hostname:8000/sap/bc/srt/wsdl/bndg_E04711310A0E55F1A0E3005056B03D6F/wsdl11/allinone/ws_policy/document?sap-client=450
    Kind Regards,
    Richard

  • Restiction on SAP Lumira user with BI_DATA_ANALYST role

    Hi,
    Is there an option to disable the SAP Lumira user with BI_DATA_ANALYST role from loading the Excel data into SAP Hana?   We would like the user to be able to create story boards and publish it on SAP LUMIRA server using HANA views but not allow him to load any flat file data.
    Thanks,
    Lakshmi

    Manish - if you are on BI4 there is no need for the SAP Integration Kit with Web Intelligence
    You can connect using the BEx Query
    For Lumira right now you can connect using the BEx query but only in the Visualize room - more enhancements are planned in 1.27 - see SAP Lumira Webcast including H1 Plans with BW Updates
    I don't think Gateway is needed in these scenarios
    Tammy

  • How i can associate my app user with database role

    In my application (oracle forms application developed in-house - We are using Oracle Forms 11gR2 with WebLogic 10.3.5 ), i want to use "application user" instead of database user.
    I have an application users table, actually, i have database users,and of course, menu application works with database roles (It was developed with oracle forms menu module), my question is, How i can associate my application user with database role, for reusing oracle forms menu funcionality?. It's possible?
    Thanks,
    Edward

    user8929172 wrote:
    In my application (oracle forms application developed in-house - We are using Oracle Forms 11gR2 with WebLogic 10.3.5 ), i want to use "application user" instead of database user.
    I have an application users table, actually, i have database users,and of course, menu application works with database roles (It was developed with oracle forms menu module), my question is, How i can associate my application user with database role, for reusing oracle forms menu funcionality?. It's possible?
    Hi Edward
    You can do this by assigning the role functionality to the application user. For example
    create the table to enter user name.
    create table to enter group name.
    create table to assign user to group.
    assign role to group.
    assign functionality for the user by coding.
    hope this helps

  • RSA SecurID and Cisco ACS integration for user(s) with enable mode

    I thought I had this problem figured out but I guess not.
    I have a Cisco 2621 router with IOS 12.2(15)T17. Behind the
    router is a Gentoo linux, RSA SecurID 6.1 and Cisco ACS 3.2.
    I use tacacs+ authentication for logging into the Cisco router
    such as telnet and ssh. In the ACS I use "external user databases"
    for authentication which proxy the request from the ACS over
    to the RSA SecurID Server. I installed RSA Agents with
    sdconf.rec file on the Cisco ACS server. I renamed "user group 1"
    to be "RSA_SecurID" group. In the "External user databases" and
    "database configurations" I assign SecurID to this "RSA_SecurID"
    group.
    Everything is working fine. In the "User Setup" I can see dynamic
    user test1, test2,...testn listed in there as "dynamic users". In
    other words, I can telnet into the router with my two-factor
    SecurID.
    The problem is that if test1 wants to go into "enable" mode with
    SecurID login, I have to go into "test1" user setting and select
    "TACACS+Enable Password" and choose "Use external database password".
    After that, test1 can go into enable mode with his/her SecurID
    credential.
    Well, this works fine if I have a few users. The problem is that
    I have about 100 users that I need to do this. The solution is
    clearly not scalable. Is there a setting from group level that
    I can do this?
    Any ACS "experts" want to help me out here? Thanks.

    That is not what I want. I want user "test1" to be able to do this:
    C
    Username: test1
    Enter PASSCODE:
    C2960>en
    Enter PASSCODE:
    C2960#
    In other words, test1 user has to type in his/her RSA token password to get
    into exec mode. After that, he/she has to use the RSA token password to
    get into enable mode. Each user can get into "enable" mode with his/her
    RSA token mode.
    The way you descripbed, it seemed like anyone in this group can go directly
    into enable mode without password. This is not what I have in mind.
    Any other ideas? Thanks.

  • 801.x WLANs authenticated via Radius and Active Directory permit any user access any WLAN

    Hi,
    I have configured several WLANs with WPA2 and 8021.x which authenticate users through Radius server (Windows Internet authentication service) that conects with an Active Directory, into the AD exists one user group for each WLAN but the problem is that any user that was added to some group can get access to any WLAN, does anyboby know if I need some configuraion on the WLC to restric that?
    thanks for your help.

    Hi Scott,
    I have done some test modifying the Radius Policy to look at called station ID and test too looking at the NAS-ID, In the first case, I change the Call Station ID Type into WLC RADIUS Authentication Servers configuration to AP MAC Address:SSID and AP Name:SSID and into the Radius Server using .*:SSID-NAME$ and SSID-NAME$ ,but it blocks access for any user. In the second case, I change the NAS-ID into WLC WLAN and interface confguration and into the radius server Policy to match all, but it doesn´t have any impact, what other test could I try?
    thanks for your help. 

  • PDF addresses not longer load and display PDF in Firefox and solutions suggest to other users with problem DON'T WORK (work fine in Chrome and Safari)

    This is an ongoing problem with other users. When putting a PDF in address window of Firefox and clicking go to address FIREFOX WILL NOT LOAD AND DISPLAY THE PDF. This problem has come up in questions from other users on your site. NONE OF THE SUGGESTED SOLUTIONS WORK! (trying either the Firefox PDF viewer or the Acrobat viewer as default viewer)
    I am using Firefox 23.0.1 (as some of the other users with the same problem). This was not a problem in the past with Firefox. Safari and Chrome continue load and display PDFs just fine from their addresses. This is a big problem as I now have to inform people who want to view my PDFs NOT TO USE FIREFOX BUT TO USE SAFARI OR CHROME.

    It appears that a link to a PDF on an internet page will not download in Firefox either!
    I went to this page:
    http://www.nasa.gov/connect/ebooks/earth_art_detail.html#.UjYEzrwsU08
    and tried to download the PDF link at the bottom of the page (Download: PDF 11.3 MB) It didn't work! Nothing happens. Tried it in Safari and it worked flawlessly.
    I have a PDF file of my work in the public_html folder on my URL. I give the address generated by that file to people who want to view my work---this works perfectly in Safari and Chrome. As to your other question, can't bookmark it if I can't get to it in Firefox.

  • Zen Touch users (and possibly non Zen Touch users) with Firmware issues click he

    i just got back from the mall.i visited the electroworld branch from which i purchased my zen. i explained to them what my problem is, at first they recharged the player in a usb port in front of me...then they also reformatted it too...told me to stick to the firmware that came with the product..the player responded and thanked them..but hr later, it blacked out again..i came back to the store manager showed him my zen ( he couldnt deny it doesnt have a problem ) and within minutes told me...they are going to give me a replacement. (the diagnosis was AUTO-OFF). they did and im very thankful. right now im charging the new player and hoping...i mean really hoping that this zen works. because im not going to waste my time again even with that warranty. if this zen is defecti've, im gonna li've with its defect..but im going to save up for the fruit's company in my next purchase..better yet why not a new pda...i can play [size="+2"]ZEN TOUCH USERS (and possibly non Zen Touch users)!!!
    OH MY GOD
    !!! I can't believe it, but after at least 5 hours of troubleshooting, I got it to work!!
    I don't know if all of these steps are necessary or not, but this is what I did in approximately this order (I'm so excited now, I'm not even sure if this is the exact order, but I'm almost positi've this is how I did it verbatim). I really, truly hope this works for everyone else.:
    ON YOUR ZEN TOUCH:
    .) Don't connect device to USB yet
    2.) Clean Disk
    3.) Format Disk
    *Don't bother with restart firmware or reboot; these options are useless.
    ON YOUR PC:
    .) Do NOT connect device to USB yet.
    2.) I did what everyone suggested and rolled my Windows Media Player to v0 (using Add/Remove programs in Control Panel), made sure I had SP2, had the latest drivers, blah blah blah. I'm not sure if this is necessary, but I also uninstalled my Firefox WMP plugin just to be safe. :smileyindifferent:
    3.) I un-installed (using Add/Remove programs in Control Panel) and re-installed my Zen Touch drivers, both my 2.0.00 and .30.03 (.30.03 is needed ONLY if you have XP Pro 64-bit edition). I'm not sure if re-installing the drivers is even necessary, but just to be safe, let's say it is. :smileyvery-happy:
    ---THIS IS THE IMPORTANT PART!---
    4.) I plugged my device into my USB port. When it prompts you whether you want to Sync the device with Windows Media Player or Take No Action, don't ignore it and close out. SYNC IT! I made the mistake of thinking that because my firmware was corrupted and my drivers weren't recognizing my Zen Touch as nothing more than a worthless hard dri've that there was no way it would sync with WMP. IT DOES
    !!! I don't know how but it freakin' does!
    5.) Open up your firmware update file and try to update again. Mine worked immediately and updated the player within seconds!
    NOTE: As mentioned on Creative's Support page, probably the only thing they were right about, your device will no longer be compatible with MediaSource. If you want to add music, you have to do it with Windows Media Player 0's Sync page now. And for the love of god, don't update Windows Media Player! It's not worth it! Winamp is way better anyways!
    Good luck everyone! I sincerely mean that. :manhappy:
    Message Edited by invisiblephrend on 06-07-2008 :32 PMusic files in it, watch movies, save medical books etc..

    I also strongly recommend that when Windows Media Player asks you whether you want to sync automatically or manually to choose the manual option. Automatic just randomly grabs music files and could likely add?music you don't want on your device.

  • AD user with no role assignment cannot login

    We have created AD users that are being authenticated through OBIEE 11g. In the AD we currently have the user, password and group information associated with all the users created.
    As per system behavior if an user's group is not mapped to a role within the EM, it should automatically be tagged with the authenticated-role which being a part of the 'BIConsumer' role will give the corresponding privileges to that user. This does not seem to be happening. Any insights on why this would be the case?
    Additionally - If there is a group associated with a AD user within the active directory itself, is it mandatory that the AD groups be associated with a role? What I mean by this is, if we have RPD level init block to map authenticated users to custom database roles imported within the RPD and EM, would they not work unless there is a direct AD group to role assignment?

    The RPD had no access set for "Authenticated Users" and "BI Consumer Role" for all subject areas as part of the presentation layer permissions, hence unless a user was assigned to a role that could access either one of the subject areas the default authentication would not work.

  • Mitigation runs against role but not user with same role assignment

    Hello, I'm currently running Compliance Calibrator 4.0. I've created a Mitigation Control and assigned a number of Risks to the Mitigation Control.
    I've then assigned the Risks in that Mitigation Control to a specific role.
    When I run the SoD check, the role no longer shows any issues. This is good and expected.
    However, when I run the SoD against a user that has that role assigned the user is reported with issues when no SoD issues should be shown.
    Am I missing something? I don't believe I need to assign Mitigation Control to the user, because one day the risk might be valid to that user, but just not for the role I'm trying to mitigate against. Many thanks.

    Hi Dylan, the system is reacting correctly.
    When you mitigate a role, you mitigate the risk associated with the role and under 'Role Analysis' you will see that this role has been mitigated.
    However when u run a User analysis, the system will still identify him if there is a 'RISK' associated with the user and this is regardless of whether the associated Role is mitigated or not because what you want to know is the risk of the user and not what roles this user has.
    You will need to specifically mitigate the User in order for the mitigation control to show against the User in the report.
    This is the same Vice Versa. when you mitigate a User, it also does not mean that all the associated Roles that the user have are mitigated. The risk associated with the roles will still appear when you do 'Role Analysis'
    Cheers!

Maybe you are looking for

  • How can I remove applications from the location service?

    In System Preferences> Security & Privacy> Privacy> Location Services are applications that ask the system to use the position of the Mac I realized, after uninstalling applications (Beta and Tweetbot Tweetbot 1.0MacAppStore and also Busycal) are not

  • How do I stop calendar from emailing alerts?

    For every calendar event I receive an email & an alert. How do I keep the alert, but stop the email? I have a hotmail email address.

  • How to design template by using subtemplate

    Hi, I want to display invoice number,customer name,invoice date in the header part and in line part I want to dispaly item name,item description,quantity,uom,extended amount.How can I achieve this.Which method should I use like subtemplate method or

  • Multiple Master Pages - how to apply to forms?

    Hello! I need to build a form with two pages, one with portrait orientation and the other one with landscape orientation. So I created two Master Pagers, one for each, with correspondent orientations. The first page is ok, following the portrait Mast

  • How to HIDE blank pages

    Hi to All, if during the printing there is a blank page how could I hide it? data.PAGE_1::ready:form - (JavaScript, client) if (data.PAGE_1.???) data.PAGE_1.presence = "hidden" Thanks & Regards, Umbeto