Describes the integration of external LDAP services with Cisco Cyber Vision to delegate user authentication. This feature enables centralized access management using Microsoft Active Directory or AD LDS services.
LDAP is an external authentication service that allows Cisco Cyber Vision to delegate user verification to directory servers.
-
Supports Microsoft Active Directory and AD LDS services.
-
Enables mapping of external directory groups to internal user roles.
-
Enables both unencrypted and secure certificate-based connections for authentication.
LDAP connections configuration and management
LDAP services can be configured and managed from
Role Mapping Guidelines
The following guidelines apply to role mapping and authentication:
-
Role Mapping: External directory groups can be mapped to Product, Operator, Auditor, or custom roles. See Users to create custom roles.
-
Admin Role: The Admin user role is reserved for internal usage and cannot be mapped to external users.
Connection Testing
After configuration, verify the LDAP connection by authenticating with valid external directory credentials using the LDAP test connection window.Authentication Source
When logging into Cisco Cyber Vision, the login format used will determine the base (i.e. internal or external) to be queried:
The login format determines the authentication source:
-
Email: Queries the internal Cisco Cyber Vision database.
-
Domain format: Using <domain_name>\<user_name> (e.g. cisco\john_doe) triggers authentication via the external directory.