Our wireless controller user is linked to Active directory. I want to create two separate groups (eg. Network Admin group and vpn group) in active directory and then I want to give permission to user from Network Admin group to login into Controller to change any content .Rest all user from vpn group can take the benefit of wireless but restrict them to change anything. Radius server (AAA) is also involved into this for authentication. Kindly help me to establish this connection.
Thanks
SD