Converting TACACS+ groups to SSO groups - BlueCat Integrity - 26.1.0

Address Manager Administration Guide

ft:locale
en-US
Product name
BlueCat Integrity
Version
26.1.0

Convert existing TACACS+ groups in Address Manager to SSO groups to migrate users and group membership claims.

Warning:
  • Before these performing the steps, you must install tacacs.net on the target Windows Server. The installation requires the .Net Framework enabled on Windows. For more information, go to https://www.tacacs.net/documentation/.
  • You must convert at least one LDAP group to an SSO admin group.
  • A TACACS+ group that has been converted to an SSO Group cannot be reverted back to a TACACS+ Group.
  1. Add TACACS+ as an authenticator in Address Manager. Refer to Adding external authenticators.
  2. Add LDAP groups in Address Manager. You can add an unlimited amount of TACACS+ groups. Refer to Adding TACACS+ user groups.
  3. Assign a specific access right to a non-admin group. Refer to Editing access rights and overrides.
  4. Log in to Address Manager as a TACACS+ user and confirm the user group and access right.
  5. Select the Settings tab in the sidebar.
  6. Under User management, select Users and groups.
  7. Select the User groups tab.
  8. Select the checkbox for the TACACS+ group.
  9. Select Actions > Convert to SSO group.
  10. Add a Change control comment, if required.
  11. Select Confirm.