McAfee EPOCDE-AA-BA Product Guide - Page 56

Configuring Windows authentication and authorization, Enabling Windows authentication in ePO Server

Page 56 highlights

7 Configuring advanced server settings Configuring Active Directory user login If you need to assign special permissions to an individual user, you can do so by creating an Active Directory group that contains only that user. Configuring Windows authentication and authorization Use these tasks to set up Active Directory User Login. Tasks • Enabling Windows authentication in ePO Server on page 56 Before more advanced Windows authentication can be used, the server must be prepared. • Configuring Windows authentication on page 56 There are multiple ways to allow users to use existing Windows account credentials within ePolicy Orchestrator. • Configuring Windows authorization on page 57 Users attempting to log on to an ePolicy Orchestrator server using Windows authentication need a permission set assigned to one of their Active Directory groups to log on successfully. Enabling Windows authentication in ePO Server Before more advanced Windows authentication can be used, the server must be prepared. To activate the Windows Authentication page in the server settings, you must first stop the ePolicy Orchestrator service. This task must be performed on the McAfee ePO server itself. Task For option definitions, click ? in the interface. 1 From the server console, select Start | Settings | Control Panel | Administrative Tools 2 Select Services. 3 In the Services window, right-click McAfee ePolicy Orchestrator Applications Server and select Stop. 4 Rename Winauth.dll to Winauth.bak. In a default installation, this file is found in C:\Program Files\McAfee\ePolicy Orchestrator \Server\bin. 5 Restart the server. When you next open the Server Settings page, a Windows Authentication option appears. Configuring Windows authentication There are multiple ways to allow users to use existing Windows account credentials within ePolicy Orchestrator. Before you begin You must have first prepared your server for Windows authentication. See Enabling Windows authentication in ePO server. How you configure these settings depends on several issues: 56 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

If you need to assign special permissions to an individual user, you can do so by creating an Active
Directory group that contains only that user.
Configuring Windows authentication and authorization
Use these tasks to set up Active Directory User Login.
Tasks
Enabling Windows authentication in ePO Server
on page 56
Before more advanced Windows authentication can be used, the server must be prepared.
Configuring Windows authentication
on page 56
There are multiple ways to allow users to use existing Windows account credentials within
ePolicy Orchestrator.
Configuring Windows authorization
on page 57
Users attempting to log on to an ePolicy Orchestrator server using Windows authentication
need a permission set assigned to one of their Active Directory groups to log on
successfully.
Enabling Windows authentication in ePO Server
Before more advanced Windows authentication can be used, the server must be prepared.
To activate the Windows Authentication page in the server settings, you must first stop the ePolicy
Orchestrator service. This task must be performed on the McAfee ePO server itself.
Task
For option definitions, click
?
in the interface.
1
From the server console, select
Start
|
Settings
|
Control Panel
|
Administrative Tools
2
Select
Services
.
3
In the
Services
window, right-click
McAfee ePolicy Orchestrator Applications Server
and select
Stop
.
4
Rename
Winauth.dll
to
Winauth.bak
.
In a default installation, this file is found in
C:\Program Files\McAfee\ePolicy Orchestrator
\Server\bin
.
5
Restart the server.
When you next open the
Server Settings
page, a
Windows Authentication
option appears.
Configuring Windows authentication
There are multiple ways to allow users to use existing Windows account credentials within ePolicy
Orchestrator.
Before you begin
You must have first prepared your server for Windows authentication. See
Enabling
Windows authentication in ePO server
.
How you configure these settings depends on several issues:
7
Configuring advanced server settings
Configuring Active Directory user login
56
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide