Nominated Discussion: Disable Local Account When NAC is Reachable

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Community Team Member
No ratings

This article is based on a discussion, Disable Local Account when NAC is reachable, posted by @BradleyFergel and answered by @Kiwi . Read on to see the discussion and solution!

 

Is there a way to disable the local account when an external authentication method is reachable? Only being able to log into the local account if it cant reach the external authentication server?

 

You can't disable an admin account directly on the administrator menu. However there's a little trick you can do:

 

First create a local user via Device > Local User Database > Users

 

kiwi_0-1659601881274.png

 

Then create a local authentication profile and add the user to it via Device > Authentication Profile

 

kiwi_1-1659601981844.png

 

Next add an administrator account for the same user and use the local authentication profile via Device > Administrators

 

kiwi_2-1659602321547.png

 

This way you can simply enable/disable the admin account by checking/unchecking the 'Enable' box on the Local User profile:

 

kiwi_3-1659602391289.png

 

Note: If you just need a fallback authentication method then you'll need to look into an authentication sequence where you can put multiple authentication methods in sequence where the firewall tries the configured methods sequentially from top to bottom and will deny access if ALL of the methods fail.

 
Rate this article:
  • 1299 Views
  • 0 comments
  • 0 Likes
Register or Sign-in
Labels
Article Dashboard
Version history
Last Updated:
‎08-18-2022 08:46 AM
Updated by: