HPE6-A84 · Question #42
You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled…
The correct answer is C. Add a custom attribute for userAccountControl to the filters in the AD authentication source. According to the ClearPass Policy Manager User Guide1, userAccountControl is a custom attribute in Active Directory that contains a set of flags that define the properties and behavior of user accounts. One of these flags is ACCOUNTDISABLE, which indicates whether the account…
Question
You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled accounts from connecting even if those users still have valid certificates. As the first part of meeting these criteria, what should you do to enable CPPM to determine where accounts are enabled in AD or not?
Options
- AAdd an Endpoint Context Server to the domain controller with actions for querying the domain
- BEnable OCSP in the EAP-TLS authentication method settings and configure an OCSP override to
- CAdd a custom attribute for userAccountControl to the filters in the AD authentication source.
- DInstall a Microsoft Active Directory extension in Aruba ClearPass Guest and set up an HTTP
How the community answered
(55 responses)- A4% (2)
- B5% (3)
- C78% (43)
- D13% (7)
Explanation
According to the ClearPass Policy Manager User Guide1, userAccountControl is a custom attribute in Active Directory that contains a set of flags that define the properties and behavior of user accounts. One of these flags is ACCOUNTDISABLE, which indicates whether the account is disabled or not. By adding this attribute to the filters in the AD authentication source, CPPM can retrieve this attribute for each user and use it as a condition in the enforcement policies to prevent users with disabled accounts from connecting even if they have valid certificates.
Topics
Community Discussion
No community discussion yet for this question.