Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ACS 4.1 dynamic users

Hello all,

I have some problems with the dynamic users. I want to move them to another group and do some changes on userid, but I also want that they are replicated then. The first is no issue, the second is, since they stay flagged as "dynamic users".

Can this be solved without deleting and recreating them?

Another question --> Can I block the button "remove dynamic users"?

regards,

Patrick

1 REPLY
Cisco Employee

Re: ACS 4.1 dynamic users

ACS won't replicate users previously set for dynamic mapping

CSCsi13785

http://cdetsweb-prd.cisco.com/apps/dumpcr?identifier=CSCsi13785&parentprogra
m=QDDTS

It stated, ACS Database replication may inappropriately flag users as
"learned dynamically" and fail to replicate them in certain cases. If we
modify the group membership for one of these users and explicitly set the
group membership, the user will still fail to replicate to the secondary ACS
server.  This is a bug.

This bug was resolved in 4.1.4.13.7.
 
Based on the above bug, if you make a change for a user present on the
external DB (the user account haven't been manually created on the ACS db)
and not on the internal ACS DB under User Setup, ACS considers it to be
still a dynamically mapped user and thus doesn't replicate it.


Also, you can not block the this tab " remove dynamic users". However, you can restrict user not to access  External User Databases section by unchecking the option under administration control >>> click on the user account and disable this option.


HTH

Jatin


Do rate helpful posts-

~BR Jatin Katyal **Do rate helpful posts**
1349
Views
0
Helpful
1
Replies
CreatePlease to create content