Cisco Unified Communications Manager Administration Guide, Release 8.5(1)
Credential Policy Default Configuration
Downloads: This chapterpdf (PDF - 106.0KB) The complete bookPDF (PDF - 13.86MB) | Feedback

Credential Policy Default Configuration

Table Of Contents

Credential Policy Default Configuration

Credential Policy Default Configuration Settings

Assigning and Configuring Credential Policy Defaults

Related Topics


Credential Policy Default Configuration


The following topics contain information on configuring credential policies:

Credential Policy Default Configuration Settings

Assigning and Configuring Credential Policy Defaults

Related Topics

Credential Policy Default Configuration Settings

In Cisco Unified Communications Manager Administration, use the User Management > Credential Policy Default menu path to configure credential policy defaults.

This chapter describes how to assign default credential policies to a credential group. See the "Related Topics" section for more information about changing credential information for individual users.

The Credential Policy Default window provides options to change the default credential policy assignment for a user and credential type (for example, end user PINs). At installation, Cisco Unified Communications Manager assigns the system Default Credential Policy to end user passwords, end user PINS, and application user passwords. The system applies the application password that you configured at installation to all application users. You can assign a new default credential policy and configure new default credentials after installation.

Tips About Configuring Credential Policy Defaults

The system provides the default credential policy to facilitate installs and upgrades. The default credential policy settings in Table 85-1 differ from the credential policy defaults settings that are described in the "Credential Policy Configuration Settings", which you use for adding a new credential policy.


Note The system does not support empty (null) credentials. If your system uses LDAP authentication, you must configure end user default credentials immediately after installation, or logins will fail.


You can also assign a new user credential policy, manage user authentication events, or view credential information for a user in the user configuration windows. For more information, see "Managing Application User Credential Information" section on page 87-8 for application users and "Managing End User Credential Information" section on page 88-10 for end users.

Using the GUI

For instructions on how to use the Cisco Unified Communications Manager Administration Graphical User Interface (GUI) to find, delete, configure, or copy records, see the "Navigating the Cisco Unified Communications Manager Administration Application" section on page 1-13 and its subsections, which explain how to use the GUI and detail the functions of the buttons and icons.

Configuration Settings Table

Table 85-1 describes the credential policy default configuration settings. See the "Related Topics" section for related information and procedures.

Table 85-1 Credential Policy Default Configuration Settings 

Field
Description

Credential User

This field displays the user type for the policy that you selected in the Find and List Credential Policy Defaults window.

You cannot change this field.

Credential Type

This field displays the credential type for the policy that you selected in the Find and List Credential Policy Defaults window.

You cannot change this field.

Credential Policy

Choose a credential policy default for this credential group.

The list box displays the predefined Default Credential Policy and any credential policies that you created, as described in the "Credential Policy Configuration" section on page 86-1.

Change Credential

Enter up to 127 characters to configure a new default credential for this group.

Confirm Credential

For verification, reenter the login credential that you entered in the Change Credential field.

User Cannot Change

Check this check box to block users that are assigned this policy from changing this credential.

You cannot check this check box when User Must Change at Next Login is checked. The default setting for this check box specifies unchecked.

User Must Change at Next Login

Check this check box to require users that are assigned this policy to change this credential at next login. Use this option after you assign a temporary credential.

You cannot check this check box when the User Cannot Change check box is checked. The default setting for this check box specifies checked.

Does Not Expire

Check this check box to block the system from prompting the user to change this credential. You can use this option for low-security users or group accounts.

If this check box is checked, the user can still change this credential at any time. When this check box is unchecked, the expiration setting in the associated credential policy applies.

The default setting for this check box specifies unchecked.


Additional Information

See the "Related Topics" section.

Assigning and Configuring Credential Policy Defaults

This section describes how to assign a new credential policy and new default credentials to a credential group. At installation, the system assigns a default credential policy to the credential groups.


Note Upgrades from 5.x releases automatically migrate application and end user passwords and PINs.


Before You Begin

To assign a default credential policy other than the predefined Default Credentials Policy, you must first create the policy. Go to the "Credential Policy Configuration" section on page 86-1 if you have not yet created the policy that you want to use.

Procedure


Step 1 Choose User Management > Credential Policy Default.

The Find and List Find and List Credential Policy Defaults window displays.

Step 2 Click the list item to change.

The Credential Policy Default Configuration window displays with the current settings.

Step 3 Enter the appropriate settings, as described in Table 85-1, using these guidelines:

To change the applied credential policy, select the policy from the drop-down list box.

To change the default credential, enter and confirm the new credential in the appropriate fields.

To change credential requirements, check or uncheck the appropriate check boxes.

Step 4 Click the Save button or the Save icon.


Next Steps

To assign a new user credential policy, manage user authentication events, or view credential information for a user, use these procedures:

Managing Application User Credential Information, page 87-8

Managing End User Credential Information, page 88-10

To configure a unique password for a user, use these procedures:

Changing an Application User Password, page 87-8

Changing an End User Password, page 88-9

Changing an End User PIN, page 88-9

The Bulk Administration Tool (BAT) allows administrators to define common credential parameters, such as passwords and PINs, for a group of users in the BAT User Template. See the Cisco Unified Communications Manager Bulk Administration Guide for more information.

End users can change PINs at the phone user pages; end users can change passwords at the phone user pages when LDAP authentication is not enabled. See the documentation for your Cisco Unified IP Phone for more information.

Additional Information

See the "Related Topics" section.

Related Topics

Assigning and Configuring Credential Policy Defaults

Credential Policy Default Configuration Settings

Credential Policy Configuration Settings, page 86-1

Changing an Application User Password, page 87-8

Changing an End User Password, page 88-9

Changing an End User PIN, page 88-9

Managing End User Credential Information, page 88-10

Managing Application User Credential Information, page 87-8

Credential Policy, Cisco Unified Communications Manager System Guide

Understanding the Directory, Cisco Unified Communications Manager System Guide

Application Users and End Users, Cisco Unified Communications Manager System Guide

Cisco Extension Mobility, Cisco Unified Communications Manager Features and Services Guide