Reference Guide

version 1.2 Zach Jennings |7
4. CPPM 6.0 Authentication sources (AD/LDAP):
Here are some tips when using AD/LDAP as an authentication source.
An AD/LDAP account is required for EAP-PEAP authentication, for group membership, and
etc.
The account used for ClearPass requires read rights to the folders/information you want to
use in role mapping.
The account used must also remain active, and should not be required to change or update
its password regularly (setup as a service account).
DO NOT use a regular user’s account for production ClearPass deployments. Think of what
happens when the original user leaves the organization and their account is deactivated. You
should always use a dedicated service account for production ClearPass deploments!