<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to limit admin login based on User Group using Microsoft LDAP on Sz/vSZ(e.g. Guestpass Access) in RUCKUS Self-Help</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-limit-admin-login-based-on-User-Group-using-Microsoft/m-p/71018#M263</link>
    <description>&lt;P&gt;This article explains how to limit admin login based on User Group using Microsoft LDAP on Sz/vSZ, in this example we will cover Guestpass Access.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;SUMMARY:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Customer wants to use Microsoft LDAP to allow admin login only for Guestpass generation based on User Group using Microsoft LDAP on Sz/vSZ.&lt;BR /&gt;&lt;BR /&gt;Validation has been done &lt;STRONG&gt;6.1.1.X&lt;/STRONG&gt; firmware version.&lt;BR /&gt;&lt;BR /&gt;We will cover below setting&amp;nbsp; from &lt;STRONG&gt;Microsoft AD&lt;/STRONG&gt; Perspective.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;User Group Mapping&lt;BR /&gt;How to find DN pattern&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;FONT size="3" color="#000000"&gt;from SZ/vSZ perspective&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Group&lt;BR /&gt;AAA&lt;BR /&gt;Search filter&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Microsoft AD User Group setting.&lt;BR /&gt;&lt;BR /&gt;From Microsoft AD open &lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Active Directory Users and Computer&lt;/STRONG&gt;.&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;User Group Mapping&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_2-1698972053504.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9617i633C382EDD5E5A32/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_2-1698972053504.png" alt="vijaykuniyal_2-1698972053504.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In &lt;STRONG&gt;Active Directory Users and Computer&lt;/STRONG&gt; select the group which needs to allowed for &lt;STRONG&gt;Guestpass&lt;/STRONG&gt; generation and Map Members to it with the &lt;STRONG&gt;Add &lt;/STRONG&gt;button.&lt;BR /&gt;&lt;BR /&gt;e.g.&lt;BR /&gt;&lt;STRONG&gt;GPASS&lt;/STRONG&gt; is the Group as below.&lt;BR /&gt;&lt;STRONG&gt;vijayguest&lt;/STRONG&gt; is the member mapped to it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_1-1698971914976.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9616i2783B812BC1E303E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_1-1698971914976.png" alt="vijaykuniyal_1-1698971914976.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;How to find right DN pattern (Group and User)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Open command Prompt and run below command one by one.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;("dsquery group -name &lt;STRONG&gt;&amp;lt;groupname&amp;gt;"&lt;/STRONG&gt;)&lt;BR /&gt;("dsquery group -name &lt;STRONG&gt;&amp;lt;username&amp;gt;"&lt;/STRONG&gt;)&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;lt;groupname&amp;gt;&lt;/STRONG&gt; is variable "&lt;STRONG&gt;GPASS&lt;/STRONG&gt;" as in below example&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_3-1698972535940.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9618i88BD5A0DC80DD7C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_3-1698972535940.png" alt="vijaykuniyal_3-1698972535940.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;lt;username&amp;gt;&lt;/STRONG&gt; is variable "&lt;STRONG&gt;Administrator&lt;/STRONG&gt;" as in below example&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_17-1698975189775.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9638i1A9001E81145CFB2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_17-1698975189775.png" alt="vijaykuniyal_17-1698975189775.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This DN pattern will be used in the AAA server setting for &lt;STRONG&gt;Search filter&lt;/STRONG&gt; and &lt;STRONG&gt;Administrator Domain&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Administrator&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Create an administrator user on SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administration&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Admin and Roles&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administrator&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;(&lt;STRONG&gt;guestpassuser&lt;/STRONG&gt; for example, this is a dummy user).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_6-1698973325056.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9621i7C8BFE83B6A6D24E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_6-1698973325056.png" alt="vijaykuniyal_6-1698973325056.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_8-1698973402014.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9623i73FE038C353E1567/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_8-1698973402014.png" alt="vijaykuniyal_8-1698973402014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Groups&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Create an Group on SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administration&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Admin and Roles&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Groups&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;With below settingas example&lt;STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Permission&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_10-1698973693554.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9625i6965B6975183574E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_10-1698973693554.png" alt="vijaykuniyal_10-1698973693554.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resources&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_11-1698973769146.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9626iDAF3CE01E42DBD8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_11-1698973769146.png" alt="vijaykuniyal_11-1698973769146.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;Administrator&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Move user to the right with the arrow to map to the group.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_12-1698973860867.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9627iC2F5C556DC54D750/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_12-1698973860867.png" alt="vijaykuniyal_12-1698973860867.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Review&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Review the setting and click OK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_13-1698974009654.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9628i6889E469E1075B21/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_13-1698974009654.png" alt="vijaykuniyal_13-1698974009654.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="2" color="#FF6600"&gt;AAA&lt;BR /&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;Create an AAA LDAP server on&lt;STRONG&gt; SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;Administration&amp;gt;&amp;gt;&amp;gt;Admin and Roles&amp;gt;&amp;gt;&amp;gt;AAA&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Turn on &lt;STRONG&gt;Default Role Mapping&lt;BR /&gt;&lt;/STRONG&gt;Select User Groupcreated as above&lt;STRONG&gt;(GPASS)&lt;BR /&gt;&lt;/STRONG&gt;Select Administrator created as above&lt;STRONG&gt;(guestpassuser)&lt;BR /&gt;&lt;/STRONG&gt;Select &lt;STRONG&gt;LDAP&lt;/STRONG&gt; from the checkbox&lt;BR /&gt;Fill &lt;STRONG&gt;Realm&lt;/STRONG&gt; as AD domain (&lt;STRONG&gt;wireless.com&lt;/STRONG&gt; for example)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_14-1698974403648.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9633i4F73B6169F08F0C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_14-1698974403648.png" alt="vijaykuniyal_14-1698974403648.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP address&lt;/STRONG&gt; of Server and Port number (&lt;STRONG&gt;389&lt;/STRONG&gt; for LDAP)&lt;STRONG&gt;&lt;BR /&gt;Base&lt;/STRONG&gt; Doamin(exact domain) and &lt;STRONG&gt;Admin&lt;/STRONG&gt; &lt;STRONG&gt;Domain&lt;/STRONG&gt; based on ds query for &lt;STRONG&gt;Administrator&lt;/STRONG&gt;.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Type LDAP &lt;STRONG&gt;Administrator&lt;/STRONG&gt; password and &lt;STRONG&gt;Confirm&lt;/STRONG&gt; password.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Fill &lt;STRONG&gt;Key Attribute: "cn"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_16-1698974944268.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9636i45516D8371586539/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_16-1698974944268.png" alt="vijaykuniyal_16-1698974944268.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="2" color="#FF6600"&gt;Search filter&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Search Filter in the below format and Click &lt;STRONG&gt;OK&lt;/STRONG&gt; to Save.(based on the &lt;STRONG&gt;dsquesy results, &lt;/STRONG&gt;&lt;FONT color="#FF0000"&gt;max character limit in the box is &lt;STRONG&gt;64&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;(objectClass=*)(memberof=CN=GPASS,CN=Users,DC=wireless,DC=com)&lt;/PRE&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_0-1698979440755.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9639i61D85ACFA0064DB7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_0-1698979440755.png" alt="vijaykuniyal_0-1698979440755.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test AAA Server&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;AD User&lt;/STRONG&gt; part of &lt;STRONG&gt;GPASS&lt;/STRONG&gt; group will pass authentication.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_1-1698979528093.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9640i2A9E27B406337DBF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_1-1698979528093.png" alt="vijaykuniyal_1-1698979528093.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AD User&lt;/STRONG&gt; not a member of &lt;STRONG&gt;GPASS&lt;/STRONG&gt; group will &lt;STRONG&gt;fail to authenticate&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_2-1698979632074.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9641i271D9A05727C4370/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_2-1698979632074.png" alt="vijaykuniyal_2-1698979632074.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Once tested verify login from the admin page as well.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LDAP User&lt;/STRONG&gt; group authentication will succeed (&lt;STRONG&gt;GPASS&lt;/STRONG&gt; in this example).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_3-1698979874927.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9642i579CA7C91B6C7EEB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_3-1698979874927.png" alt="vijaykuniyal_3-1698979874927.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Authentication will fail for non LDAP Group User (&lt;STRONG&gt;GPASS&lt;/STRONG&gt; in this example).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_5-1698980016961.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9644iBA70B5ED1E20F9C7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_5-1698980016961.png" alt="vijaykuniyal_5-1698980016961.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 01:29:12 GMT</pubDate>
    <dc:creator>vijaykuniyal</dc:creator>
    <dc:date>2023-11-15T01:29:12Z</dc:date>
    <item>
      <title>How to limit admin login based on User Group using Microsoft LDAP on Sz/vSZ(e.g. Guestpass Access)</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-limit-admin-login-based-on-User-Group-using-Microsoft/m-p/71018#M263</link>
      <description>&lt;P&gt;This article explains how to limit admin login based on User Group using Microsoft LDAP on Sz/vSZ, in this example we will cover Guestpass Access.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;SUMMARY:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Customer wants to use Microsoft LDAP to allow admin login only for Guestpass generation based on User Group using Microsoft LDAP on Sz/vSZ.&lt;BR /&gt;&lt;BR /&gt;Validation has been done &lt;STRONG&gt;6.1.1.X&lt;/STRONG&gt; firmware version.&lt;BR /&gt;&lt;BR /&gt;We will cover below setting&amp;nbsp; from &lt;STRONG&gt;Microsoft AD&lt;/STRONG&gt; Perspective.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;User Group Mapping&lt;BR /&gt;How to find DN pattern&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;FONT size="3" color="#000000"&gt;from SZ/vSZ perspective&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Group&lt;BR /&gt;AAA&lt;BR /&gt;Search filter&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Microsoft AD User Group setting.&lt;BR /&gt;&lt;BR /&gt;From Microsoft AD open &lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Active Directory Users and Computer&lt;/STRONG&gt;.&lt;BR /&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;User Group Mapping&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_2-1698972053504.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9617i633C382EDD5E5A32/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_2-1698972053504.png" alt="vijaykuniyal_2-1698972053504.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In &lt;STRONG&gt;Active Directory Users and Computer&lt;/STRONG&gt; select the group which needs to allowed for &lt;STRONG&gt;Guestpass&lt;/STRONG&gt; generation and Map Members to it with the &lt;STRONG&gt;Add &lt;/STRONG&gt;button.&lt;BR /&gt;&lt;BR /&gt;e.g.&lt;BR /&gt;&lt;STRONG&gt;GPASS&lt;/STRONG&gt; is the Group as below.&lt;BR /&gt;&lt;STRONG&gt;vijayguest&lt;/STRONG&gt; is the member mapped to it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_1-1698971914976.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9616i2783B812BC1E303E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_1-1698971914976.png" alt="vijaykuniyal_1-1698971914976.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;How to find right DN pattern (Group and User)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Open command Prompt and run below command one by one.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;("dsquery group -name &lt;STRONG&gt;&amp;lt;groupname&amp;gt;"&lt;/STRONG&gt;)&lt;BR /&gt;("dsquery group -name &lt;STRONG&gt;&amp;lt;username&amp;gt;"&lt;/STRONG&gt;)&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;lt;groupname&amp;gt;&lt;/STRONG&gt; is variable "&lt;STRONG&gt;GPASS&lt;/STRONG&gt;" as in below example&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_3-1698972535940.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9618i88BD5A0DC80DD7C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_3-1698972535940.png" alt="vijaykuniyal_3-1698972535940.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;lt;username&amp;gt;&lt;/STRONG&gt; is variable "&lt;STRONG&gt;Administrator&lt;/STRONG&gt;" as in below example&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_17-1698975189775.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9638i1A9001E81145CFB2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_17-1698975189775.png" alt="vijaykuniyal_17-1698975189775.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This DN pattern will be used in the AAA server setting for &lt;STRONG&gt;Search filter&lt;/STRONG&gt; and &lt;STRONG&gt;Administrator Domain&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Administrator&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Create an administrator user on SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administration&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Admin and Roles&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administrator&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;(&lt;STRONG&gt;guestpassuser&lt;/STRONG&gt; for example, this is a dummy user).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_6-1698973325056.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9621i7C8BFE83B6A6D24E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_6-1698973325056.png" alt="vijaykuniyal_6-1698973325056.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_8-1698973402014.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9623i73FE038C353E1567/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_8-1698973402014.png" alt="vijaykuniyal_8-1698973402014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;Groups&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Create an Group on SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Administration&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Admin and Roles&lt;/STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&lt;STRONG&gt;Groups&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;With below settingas example&lt;STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Permission&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_10-1698973693554.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9625i6965B6975183574E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_10-1698973693554.png" alt="vijaykuniyal_10-1698973693554.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resources&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_11-1698973769146.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9626iDAF3CE01E42DBD8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_11-1698973769146.png" alt="vijaykuniyal_11-1698973769146.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;Administrator&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Move user to the right with the arrow to map to the group.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_12-1698973860867.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9627iC2F5C556DC54D750/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_12-1698973860867.png" alt="vijaykuniyal_12-1698973860867.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Review&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Review the setting and click OK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_13-1698974009654.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9628i6889E469E1075B21/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_13-1698974009654.png" alt="vijaykuniyal_13-1698974009654.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="2" color="#FF6600"&gt;AAA&lt;BR /&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;Create an AAA LDAP server on&lt;STRONG&gt; SZ/vSZ GUI&amp;gt;&amp;gt;&amp;gt;Administration&amp;gt;&amp;gt;&amp;gt;Admin and Roles&amp;gt;&amp;gt;&amp;gt;AAA&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Turn on &lt;STRONG&gt;Default Role Mapping&lt;BR /&gt;&lt;/STRONG&gt;Select User Groupcreated as above&lt;STRONG&gt;(GPASS)&lt;BR /&gt;&lt;/STRONG&gt;Select Administrator created as above&lt;STRONG&gt;(guestpassuser)&lt;BR /&gt;&lt;/STRONG&gt;Select &lt;STRONG&gt;LDAP&lt;/STRONG&gt; from the checkbox&lt;BR /&gt;Fill &lt;STRONG&gt;Realm&lt;/STRONG&gt; as AD domain (&lt;STRONG&gt;wireless.com&lt;/STRONG&gt; for example)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_14-1698974403648.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9633i4F73B6169F08F0C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_14-1698974403648.png" alt="vijaykuniyal_14-1698974403648.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP address&lt;/STRONG&gt; of Server and Port number (&lt;STRONG&gt;389&lt;/STRONG&gt; for LDAP)&lt;STRONG&gt;&lt;BR /&gt;Base&lt;/STRONG&gt; Doamin(exact domain) and &lt;STRONG&gt;Admin&lt;/STRONG&gt; &lt;STRONG&gt;Domain&lt;/STRONG&gt; based on ds query for &lt;STRONG&gt;Administrator&lt;/STRONG&gt;.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Type LDAP &lt;STRONG&gt;Administrator&lt;/STRONG&gt; password and &lt;STRONG&gt;Confirm&lt;/STRONG&gt; password.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Fill &lt;STRONG&gt;Key Attribute: "cn"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_16-1698974944268.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9636i45516D8371586539/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_16-1698974944268.png" alt="vijaykuniyal_16-1698974944268.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="2" color="#FF6600"&gt;Search filter&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Search Filter in the below format and Click &lt;STRONG&gt;OK&lt;/STRONG&gt; to Save.(based on the &lt;STRONG&gt;dsquesy results, &lt;/STRONG&gt;&lt;FONT color="#FF0000"&gt;max character limit in the box is &lt;STRONG&gt;64&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;(objectClass=*)(memberof=CN=GPASS,CN=Users,DC=wireless,DC=com)&lt;/PRE&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_0-1698979440755.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9639i61D85ACFA0064DB7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_0-1698979440755.png" alt="vijaykuniyal_0-1698979440755.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test AAA Server&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;AD User&lt;/STRONG&gt; part of &lt;STRONG&gt;GPASS&lt;/STRONG&gt; group will pass authentication.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_1-1698979528093.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9640i2A9E27B406337DBF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_1-1698979528093.png" alt="vijaykuniyal_1-1698979528093.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AD User&lt;/STRONG&gt; not a member of &lt;STRONG&gt;GPASS&lt;/STRONG&gt; group will &lt;STRONG&gt;fail to authenticate&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_2-1698979632074.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9641i271D9A05727C4370/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_2-1698979632074.png" alt="vijaykuniyal_2-1698979632074.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Once tested verify login from the admin page as well.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LDAP User&lt;/STRONG&gt; group authentication will succeed (&lt;STRONG&gt;GPASS&lt;/STRONG&gt; in this example).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_3-1698979874927.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9642i579CA7C91B6C7EEB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_3-1698979874927.png" alt="vijaykuniyal_3-1698979874927.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Authentication will fail for non LDAP Group User (&lt;STRONG&gt;GPASS&lt;/STRONG&gt; in this example).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaykuniyal_5-1698980016961.png" style="width: 999px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9644iBA70B5ED1E20F9C7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vijaykuniyal_5-1698980016961.png" alt="vijaykuniyal_5-1698980016961.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 01:29:12 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-limit-admin-login-based-on-User-Group-using-Microsoft/m-p/71018#M263</guid>
      <dc:creator>vijaykuniyal</dc:creator>
      <dc:date>2023-11-15T01:29:12Z</dc:date>
    </item>
  </channel>
</rss>

