Question about ACS 5.1 and user account expiration

Hi All,
Is there a setting on ACS 5.1 where you can configure the user account's expiration? Speaking of users locally configured on the ACS.
If not, can you accomplish this with an external db such as MS AD? How ?
We are looking for a way to manage our guest's hotspot so what we can create temporary users without having to purchase any aditional hardware/software.
Thanks in advance,
Raga

Raga,
Here is the answer to your first questions -
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/release/notes/acs_51_rn.html#wp122068
As far as being able to do this in AD it is possible you can look at the following documentation which shows how to configure AD attributes, I have helped a customer retrieve the lockouttime attribute in his AD environment, I dont think this attribute is present in the 2003 DC because I was unable to replicate this attribute.
Another step would be to use useraccountcontrol -
http://support.microsoft.com/kb/305144 - if set a simple condition that if this value is 512 you can permit access, when you lock the account it will add the status of disable to the type of account if it is 512 (Normal_Account) it will equal 514. The most secure is to see what value you have for the guest account by retrieving the attribute after you create the account, create a condition that matches this account.
Let me know if this helps!
Tarik

Similar Messages

  • Checking Computer AND User Account against AD without TLS

    Hi Folks,
    i am working on a customer site with 5500/ACS5.2/AD/WZC. The Customer looks for a good Authentication Scenario but decides against TLS. So we tested PEAP with checking the AD for a valid Computer Account and User Auth. But, if i use a Laptop with no Domain Computer Account but a valid User Account, i  can gain Access. Is it possible that the ACS can check for a valid Computer AND User Account and successes the Client only if both Accounts are available and valid?
    Regards, Michael

    Hi Nicolas, thx for this Hint. I did  today the Host Lookup and "was machin auth" thing, but anyway, my own Laptop
    that is not in the Domain can connect with a Domain User ID to the Network. Any Hint or Trick? I saw on other Discussions you referred to that some Users did an AD Rejoin, what do you think?
    Regards, Michael

  • Can't Change Lock Screen Background Image and User Account Picture in Windows 8.1.

    I am running Windows8.1 Single Language with windows activated. Upgraded from Window 8 to Windows 8.1.
    Lenovo Y410p.
    4th generation Intel® Core™ i7-4700MQ (2.40GHz 1600MHz 6MB) with 16GB RAM.
    NVIDIA® GeForce® GT750M 2GB .
    I tried all methods that I found on web included :
    1. http://www.askvg.com/fix-cant-change-lock-screen-background-and-user-account-picture-in-windows-8/
    2. http://answers.microsoft.com/en-us/windows/forum/windows8_1-desktop/lockscreen-issues-on-windows-81/c51f570a-7a69-4e92-8348-3ebbed778592
    3. I deleted the C:\ProgramData\Microsoft\Windows\SystemData file and folder
    4. I restored the Libraries Features.
    5. I run SFC / Scannow 3 times but get no error.
    6.  I created a new local account but the same problem shows up. (I'm using live for main account.)
    Now, Please tell me what should I do, Thanks.

    Hi,
    First of all, please run the command slmgr.vbs /dlv
    After that, check the License status if it is licensed.
    Is there any error message when you couldn't change lock background or this option just grey out?
    Roger Lu
    TechNet Community Support

  • Check for Updates and User Account Control

    With Adobe Reader the 'Check for Updates' function under Help does not appear to function when 'User Account Control (UAC)' in Windows Vista is turned on.
    When UAC is turned off, the 'Check for Updates' works, and if there an update is available for Adobe Reader, it will download and install.
    Other programs that update software funtion with UAC turned on, albeit with the additional dialog boxes that UAC brings, namely the CTL/ALT/DEL and user account logon (when applicable.)
    Without updating the Adobe Reader software, users are leaving themeselves open to vulnerabilities.  Without UAC turned on, users are also leaving themselves open to certain risks.  So there appears to be a dilemma presented.
    Does anyone know if/when Adobe will be changing the 'Check for Updates' functionality so it will behave more in-line with the UAC functionality?
    Thank you in advance for your time and attention.

    With UAC enabled, I start Adobe Reader, click on Help, and there is no selection for updating.  There is nothing for me to click.  Additionally, in Edit, Preferences, Updater, "Do not download or install updates automatically" is selected, and everything on the right pane is greyed-out.
    With UAC disabled, I start Adobe Reader, click on Help, and there is a selection for 'Check for Updates.'  In Edit, Preferences, Updater, I can select the various methods of downloading/updating Adobe Reader.  The option to download the update but not install was selected, as I wanted it to be.
    Finally, I noticed that the notice from Adobe, 'Update is ready to install,' appears in the Windows tray.  And it is this point that somewhat changes the serverity of the problem, that is, while 'Check for Updates' is not available when UAC is enabled, it appears that Adobe can still be updated through the automatic download feature.  The only problem with this is that I cannot tell if the update was downloaded while UAC was enabled (probably not since the download setting says not to) or while UAC was disabled.
    In any case, it still does not appear that our clients can get their Adobe Reader software updated while UAC is enabled.  And this represents a security dilemma for us.

  • HT201263 What will i do?screenshot There is a problem with your iPhone. Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country. To find your nearest Apple Store, cli

    What will i do? ITune screenshot is as follows >
    There is a problem with your iPhone. Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country. To find your nearest Apple Store, click here.

    Do what it said to do.
    "Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country. "

  • TS1814 There is a problem with your iPhone. Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country. To find your nearest Apple Store, click here.

    There is a problem with your iPhone.
    Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country.
    To find your nearest Apple Store, click here.
    Please help me i can aktivate my phone imei 012423006333181.

    There is a problem with your iPhone.
    Please visit the Service Answer Center to find answers to all your questions about service options, warranty and other processes in your country.
    To find your nearest Apple Store
    no imei also

  • Mavericks server alerts and User account questions

    Hi
    I'm looking for more detailed information about setting up Alerts in Mavericks Server, plus I seem to have a strange problem with new user accounts when setting up.
    More Info.
    I have a Mac Mini acting almost 100% exclusively as a Time Machine backup device with encryption of three portable computers on a wired network.  This was originally set up three years using Snow Leopard Server and a 2Tb external FireWire Drive.
    The external drive is now proving too small, and in any case is showing the possible first signs of failure when tested, so the intention is to replace it with a RAID of some sort, probably a 2-drive RAID 1 device but if the budget allows we might be able to look at RAID 5 or 6 units.
    It seems a good opportunity to clean install Mavericks Server on the Mini, so I've set up a test station on my MacBook Pro with my Mac Pro (both running 10.9.2) as a test backup client.  The Server OS is on an external FireWire boot drive, and the TM backup folders are on another external, in this case a USB 3.0
    For obvious reasons there does not seem to be any reason to turn on more services than absolutely necessary, so just Time Machine and File Sharing for the moment.  All works well but I can't seem to get Alerts working.  I've listed 3 different eMail addresses (all mine) for the alerts to be sent to, and I have two Admin Accounts for Notifications, both using the same AppleID I set the Server software up with.  I've gone through the rather sparse setup help information carefully, and there is no information about additional services being required, although I did try setting up the Mail client (tested sending and receiving) on the Server and having it running whilst the backups were being tested.
    As I said, the test backups went fine and when I disconnected the backup drive from the Server to simulate a failed drive the TM on the Mac Pro client showed an alert saying the backup drive could not be found.  However, there were no emails or Notifications received, either on the Mac Pro or my iPhone from the Server.
    There seems to be minimal amount of information available about the workings of Mavericks Server, but I have gone through what I can additionally find online about Mountain Lion Server, with no real indication of what it is that I am missing.  The only instructions seem to be exactly what I've done, so your advice would be appreciated.
    Another thing that puzzles me, is that when restarting the MacBook Pro I get all the Admin and Standard User Accounts (created in Server.app) showing at the login screen.  This is only four Accounts in total, so what would happen if this was 50 Users?  If I click on the 'User' tab in Server.app I get 83 User Accounts showing, but that was not the case until this evening, as only the Admin and Stardard User Accounts I had set up were visible.
    It's obviously possible that I've mucked up the install and basic setup somehow, but I can't see that anything I've done would have these effects as I've been careful to follow the options put in front of me.
    Thank you in advance.

    There's nothing to fetch. You assign the value from the function GET_APPLICATION_PROPERTY(USERNAME); as you would any value returned from a function.
    DECLARE
       myVar    VARCHAR2(50);
    BEGIN
       myVar := GET_APPLICATION_PROPERTY(USERNAME);
    END;Hope this helps.
    Craig...
    -- If my response or the response of another is helpful or answers your question please mark the response accordingly. Thanks!

  • I have three user accounts on one computer. On only one account when I when I check Help - About fire fox only one user account says apply update and won't apply. The other two work fine.

    One of three user accounts on the same computer appears to not be updating to 8.0.1 correctly. One admin and one none admin user account says it is up-to-date. The other non-admin user account, under Help About Firefox says apply update, but won't.

    As long as you installed MS Office into its default location (the top level /Applications folder) it will be available to all user accounts on the Mac.
    As far as licensing is concerned you only have to enter the license code once, which you should do right after installing MS Office, in the same admin account you installed it from, by opening any one of the MS Office applications.  There is no additional licensing required for additional user accounts on the same Mac.
    Each user account is able to run the Office apps.  The only thing you will have to do is go through an initial setup screen in each user account (but this setup does NOT involve entering any additional license codes).
    You may have problems if you installed MS Office in a particular user account (i.e. NOT in the top level /Applications folder).

  • CD/DVD Icon and User Account question

    I'm a noob with an iBook G3 and have a couple questions, since I just purchased it used and managed to get it up and running.
    Firstly, how does one open the CD/DVD player tray? There's no icon on the desktop or options I can find to add one. I did check to make sure the settings were set to display all drives and it does show in the System Info under ATA. So far, the only solution I've found is using the paper clip method and would rather have options.
    Secondly, the person who had it previous has a user account, and I was wondering how to remove/reset to make it my own. I have the OS X install CD as well as the OS 9 install disks. Obviously, question one will likely help with question two. Thanks!

    You really need the disc.
    You can go to System Preferences > Accounts and set up a new account, being sure to give it Administrative privileges. Log out and log in as the new user. Then you can delete the other account.
    The original owner should have given you the Tiger Install disc(s) as part of the deal or should have erased Tiger off the hard drive and reinstalled the version for which you have the Install CD.

  • When I click on the icon to start firefox, the screen dims and I get this question in a dialogue box from User Account Control....."Do you want to allow the following program to make changes to this computer"

    Every time I start firefox

    '''If you have Windows-7: Home Basic and Home Premium this works.'''
    1. Create a new text file
    2. Copy the text below into it.
    <code>
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=dword:00000000
    </code>
    3. Save as, e.g. DisableUACadmin.reg The reg extension is recognized by the registry editor.
    4. Double-click your file and accept everything.Then do PART II below.
    '''If you have Windows-7: Professional (Business), Enterprise and Ultimate Editions this works.'''
    1. From the START MENU open the Control Panel and click on the Administrative Tools icon.
    2. Double click on Local Security Policy to open it.
    3. Browse down to Local Policies and then down to Security Options
    4. In the list find: “User Account Control: Behavior of the elevation prompt for administrators in Admin Approval
    Mode” and double-click on it.
    5. Using the dropdown window change the setting to “Elevate without prompting”.
    6. Close out all your windows and do PART II below
    '''PART II'''
    For all versions of Windows-7, now you can right-click the FireFox icon and select properties. Click on the Compatibility tab and select "Run this program as an Administrator".
    No more UAC for Firefox.

  • Have a question about how to set up users and what they access

    I have just loaded logic studio on my computer on my admin account but i dont want it on the any other account and when i log in to another account on the same computer the program shows up. How do you **** let the admin account use the program and not the users? what do i have to set and where? do i need to go into users accounts or sharing? i cant seem to find anything. thanks for the help.

    Try looking at Parental Controls, in >System Preferences...>Accounts.
    Alternatively, you could put Logic in your user folder (/Users/your user name/Applications) (you'll most likely have to make that Applications folder, as well as make sure permissions are set so only you can access it, by using the "Get Info" window.

  • Questions about my MacBook Pro and Apple Support.

    I was an early adopter of the Intel Mac Platform. Got my first Mac (my MacBook Pro) in April 06. It was not part of the battery recall, but I have had numerous problems. I cannot keep the machine running more than 3-5 hours without it shutting down or just locking up. The case has popped slightly (about 1mm) open on the front left. I cannot use the function keys for the heat. And I know that I need to use Apple Support, but let me tell you: I have not been impressed with Apple Support.
    My Mac was sent back for "repair" in October, and returned to me less than 6 days later. When I received it, it had a preloaded user account (complete with password!) for a user (not me) that I didn't recognize. And still had the same heat/random shutdown symptoms. Upon calling Apple Support, I was told that there wasn't anything that could be done. In fact, on one phone call I was just flat-out told that I should "just go buy another one". I could go on at length about my experiences with Apple Support.
    So here is my question:
    Is there a magic phone number, person I can contact to actually get something done about this? I have had less than 3 total months of usable time on my Mac. (I have been dealing with Apple Support since last June.) Please help. I just want my Mac to work. I know that this is just a fluke; and that my woes are the exception, not the rule.
    Thanks
    MacBook Pro Mac OS X (10.4.8)
    MacBook Pro Mac OS X (10.4.8)
    MacBook Pro   Mac OS X (10.4.8)  

    Your choices are to continue trying to work this out through your local Apple retailer or contact AppleCare directly.
    There's little anyone here can do to help you. These Discussions are user-to-user help. All the available contact information is available by clicking on the Contact Support link at the bottom of this page.

  • Disk password and user accounts

    I have a Macbook Pro (with Mavericks), and my disk is encrypted.
    When I power on my computer, I get these options:
    1. Log in with my profile/user account OR
    2. Enter the Disk Password
              followed by: log in with my profile/user account
    What I am confused about is this: How can I log into my account both with and without entering the Disk Password, and there doesn't seem to be any difference between the two? Sorry if this is a dumb question, but if my whole drive is encrypted (I only have one partition), shouldn't I be required to enter the Disk Password before I can log in with a user account?
    I created another account (non-admin) and made sure it doesn't have automatic access to the disk (in the FireVault settings). This account can also log in just fine before I enter the Disk Password, or after I enter it.
    Another weird thing that might be connected to this is that when I run the Disk Utility when my computer boots up (Cmd+R), it says my partition is encrypted + journaled, but when I run Disk Utility from within Mavericks, it says it's only journaled, NOT encrypted as well. The partition is named after my dog (I know...), so there's no confusion of the "disk1" "disk2" sort...
    Thanks in advance!!!

    Hey Melophage,
    thanks for your reply!
    I encrypted the disk under Mountain Lion, then decrypted, erased, and encrypted again under Mavericks.
    The reason for this is that I had some issues with super slow startup as well as the log in screen after sleep (the cursor in the password field would be blinking for 25-30 secs without responding to the keyboard, then the screen would go black, then come on again, and I would be able to log in…). I couldn’t identify any apps or processes that were responsible for these issues.
    When I upgraded to Mavericks, the issue went away for a week or so, then came back. So, I decrypted, erased the drive, encrypted, and now have the “double” login options.

  • Sharing Itunes library between an admin and user account on one imac G5

    Hello,
    Please forgive the repetitive question. i have set up an admin and a user account on my iMac. I set the itunes library to users/shared/music/itunes/itunes library on both accounts. The music shows up on the admin account but not the user account.
    Can anyone give a quick step by step including obscure settings that may need to be altered so that I can finally get this pesky stress monkey off my shoulder!
    Thanks!
    iMac G5   Mac OS X (10.4.3)   Ipod video 30Gb

    Hi,
    Someone recently poasted a similar problem as yours.
    Here's the discussion and solution:
    http://discussions.apple.com/message.jspa?messageID=1192454

  • Email name and user account pictures keep changing

    My wife and I share contacts and calendars using my iCloud account. She syncs her notes and reminders using her iCloud account. This seems to work fine, but a problem has arisen that I suspect is related to this setup that I don't know how to resolve. When I send an email from my iCloud account it now has a from address of "my wife's name <[email protected]>" instead of "my name <[email protected]>". Also the account login picture for my Mac's user account has been replaced with hers. The latter I can reset (I don't know how to fix the former) but eventually the problem seems to recur.  I'm not sure if this is related but our contacts list identifies my address book card with the "this is me" tag.

    #1 I am 99.5% sure (but only 99.5% if you aren't a gambling man) that when you delete a user's account using the accounts preferences all their stuff gets put into a "deleted users" folder in the users directory on the computer, so it is still all there until you trash that folder. Their account is gone but their files are still around.
    #2 I don't actually have an "applications" folder in my account, there is just one at the main directory level, so I don't think each user necessarily has one by default. However, each user has a bunch of preferences so when I start an application it comes up with my preferences. Another user will have the application come up with their preferences. That's not to say I couldn't have an application in my account area, but I could in theory have an application tucked away in any folder or subfolder and not readily identifiable as such. Any applications not in the general applications folder usually won't be accessable to other users so unless you're logging as that old user you may not even know about applications there.

Maybe you are looking for

  • Ipod 4th gen affected by ios6

    i have had my ipod 4th gen for 11 months and recently it had started to play up and so i went to the apple store who agreed and replaced it with a new one which i was unable to pick up until the day after the launch of the new iphone as they had run

  • Poor iPhone video output from QT Pro

    I am creating videos for my website using the File > Export for Web option in QuickTime Pro. My problem is with the generated file for the iPhone "myfile-iPhone-cell.3gp". The video generated for the iPhone is very poor quality - it is very pixelated

  • ME22N Item Overview - Field of Netvalue Display.

    Hi Experts,    When Executing Me22n the netvalue field (MEPO1211-NETPR)  in the Table control of Item overview is not displayed in the production server. But it is displayed in the quality server. We could not understand the issue. Please advice what

  • E51 Unable to perform bluetooth operation.

    Hi Team, I am a proud owner of Nokia E51 from last one year,i am facing issue in turning on the bluetooth from past few day . Whenever i try to turn on the bluetooth it gives an error message "Unable to perform bluetooth operation." I tried both soft

  • Unexpected error java.io.Ioexception:stream already open

    I am getting the above error when registering on whatsapp.  Whatsapp does not work through service provider but works on wifi. Please help urgently.