Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Domain Admin accout for ACS

Hi, Everybody. Recently I am installing ACS for one of my customer who can not give me the domain administrator account to run ACS service. Anyone knows that is there any workaround for this? Thanks.

2 REPLIES
Silver

Re: Domain Admin accout for ACS

It's mandatory to have the domain administrator account to run ACS service.Without domain administrator account the ACS service cannot be used.

Refer the ACS config gide in the url below:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/installation/guide/windows/install.html

New Member

Re: Domain Admin accout for ACS

The doc says that BUT We have it happily running with the ACS service account as a member of "domain users" only, membership of the local admins group on the ACS server(s) and additional user rights granted via GPO - "log on as a service", "log on as a batch job", "act as part of the operating system" - It all depends on the DACLs set on AD - the ACS account needs to be able to bind to AD and read attributes.

Regards

Andy

150
Views
0
Helpful
2
Replies