CPPM Identity|sso || local user || end point || Static Host Lists | role and role mapping in hindi

Опубликовано: 21 Май 2026
на канале: 1Minute Security
90
0

To authenticate local users from a particular service, include Local User Repository among the authentication sources.
This chapter provides details on the settings required to configure ClearPass Policy Manager Identify settings.

The Policy Manager database supports storage of user records when a particular class of users is not present in a central user repository (for example, when there is neither an Active Directory nor any other database).

The Single Sign-On (SSO) settings on the Single Sign-On page allows ClearPass users that have signed in to ClearPass Policy Manager to access the Onboard, Guest, and Insight applications and Policy Manager administration settings without reauthenticating. ClearPass provides single sign-on support using the Security Assertion Markup Language (SAML).

This feature also provides differentiated single sign-on access for Guest web login and Guest Operator login

ClearPass Policy Manager lists all local users in the Local Users page.

You can also add, import, export, set password policies, and configure the conditions for disabling accounts for the local users using the links provided at the top-right corner of the Local Users page

About Static Host Lists
You can configure primary and backup servers, session details, and the list of static hosts for Static Host List authentication sources.

A static host list often functions, in the context of the service, as a white list or a black list. Therefore, static host lists are configured independently at the global level.

A static host list comprises a named list of MAC addresses or IP addresses, which can be invoked in the following ways:

 In service and role-mapping rules as a component.
 For non-responsive services on the network (for example, printers or scanners), as an authentication source. For more information, see Adding a Static Host List as an Authentication Source.


Only static host lists of type MAC address are available as authentication sources.After authenticating a request, a Policy Manager service invokes its role-mapping policy, resulting in assignment of a role(s) to the client. This role becomes the identity component of enforcement policy decisions.



A service can be configured without a role-mapping policy, but only one role-mapping policy can be configured for each service
Identity Roles Architecture and Workflow
Roles can range in complexity from a simple user group (for example, Finance, Engineering, or Human Resources) to a combination of a user group with some dynamic constraints (for example, “Night Shift Worker,” an employee in the Engineering department who logs in through the network device between 8:00 p.m. and 5:00 a.m on weekdays). It can also apply to a list of users.

A Role-Mapping Policy reduces client (user or device) identity or attributes associated with the request to Role(s) for Enforcement Policy evaluation. The roles ultimately determine differentiated access.
Adding and Modifying Roles
Roles exist independently of an individual service and can be accessed globally through the role-mapping policy of any service.

Policy Manager lists all available roles in the Roles page.