McAfee EPOCDE-AA-BA Product Guide - Page 57

Configuring Windows authorization, Permission Sets

Page 57 highlights

Configuring advanced server settings Configuring Active Directory user login 7 • Do you want to use multiple domain controllers? • Do you have users spread across multiple domains? • Do you want to use a WINS server to look up which domain your users are authenticating against? Without any special configuration, users can authenticate using Windows credentials for the domain that the McAfee ePO server is joined to, or any domain that has a two-way trust relationship with the McAfee ePO server's domain. If you have users in domains that don't meet that criteria, you must configure Windows authentication. For option definitions, click ? in the interface. Task 1 Click Menu | Configuration | Server Settings, then select Windows Authentication from the Settings Categories list. 2 Click Edit. 3 Specify whether you want to use one or more Domains, one or more Domain controllers, or a WINS server. Domains must be provided in DNS format. (e.g. internaldomain.com) Domain controllers and WINS servers must have fully-qualified domain names. (e.g. dc.internaldomain.com) You can specify multiple domains or domain controllers, but only one WINS server. Click + to add additional domains or domain controllers to the list. 4 Click Save when you are finished adding servers. If you specify domains or domain controllers, the McAfee ePO server will attempt to authenticate users with servers in the order they are listed. It starts at the first server in the list and continues down the list until the user authenticates successfully. Configuring Windows authorization Users attempting to log on to an ePolicy Orchestrator server using Windows authentication need a permission set assigned to one of their Active Directory groups to log on successfully. Task For option definitions, click ? in the interface. 1 Click Menu | User Management | Permission Sets. 2 Either choose an existing permission set from the Permission Sets list and click Edit in the Name and users section, or click Actions | New. 3 Select any individual users the permission set should apply to. 4 Select a Server name from the list and click Add. 5 In the LDAP browser, navigate through the groups and select the groups to which this permission set should apply. Selecting an item in the Browse pane will display the members of that item in the Groups pane. You can select any number of those groups to receive the permission set dynamically. Only members from one item at a time may be added. If you need to add more, repeat steps 4 and 5 until you are finished. 6 Click Save. The permission set will now be applied to all users from the groups you specified logging on to the server using Windows authentication. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Do you want to use multiple domain controllers?
Do you have users spread across multiple domains?
Do you want to use a WINS server to look up which domain your users are authenticating against?
Without any special configuration, users can authenticate using Windows credentials for the domain
that the McAfee ePO server is joined to, or any domain that has a two-way trust relationship with the
McAfee ePO server's domain. If you have users in domains that don't meet that criteria, you must
configure Windows authentication.
For option definitions, click
?
in the interface.
Task
1
Click
Menu
|
Configuration
|
Server Settings
, then select
Windows Authentication
from the
Settings Categories
list.
2
Click
Edit
.
3
Specify whether you want to use one or more Domains, one or more Domain controllers, or a WINS
server.
Domains must be provided in DNS format. (e.g.
internaldomain.com
) Domain controllers and
WINS servers must have fully-qualified domain names. (e.g.
dc.internaldomain.com
)
You can specify multiple domains or domain controllers, but only one
WINS server. Click
+
to add additional domains or domain controllers to
the list.
4
Click
Save
when you are finished adding servers.
If you specify domains or domain controllers, the McAfee ePO server will attempt to authenticate users
with servers in the order they are listed. It starts at the first server in the list and continues down the
list until the user authenticates successfully.
Configuring Windows authorization
Users attempting to log on to an ePolicy Orchestrator server using Windows authentication need a
permission set assigned to one of their Active Directory groups to log on successfully.
Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
User Management
|
Permission Sets
.
2
Either choose an existing permission set from the
Permission Sets
list and click
Edit
in the
Name and users
section, or click
Actions
|
New
.
3
Select any individual users the permission set should apply to.
4
Select a
Server name
from the list and click
Add
.
5
In the LDAP browser, navigate through the groups and select the groups to which this permission
set should apply.
Selecting an item in the
Browse
pane will display the members of that item in the
Groups
pane. You
can select any number of those groups to receive the permission set dynamically. Only members
from one item at a time may be added. If you need to add more, repeat steps 4 and 5 until you are
finished.
6
Click
Save
.
The permission set will now be applied to all users from the groups you specified logging on to the
server using Windows authentication.
Configuring advanced server settings
Configuring Active Directory user login
7
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
57