RADIUS attributes for users or groups
You can apply RADIUS attributes to users or groups. RADIUS attributes that are set for a user take precedence over attributes that are set for the groups to which the user belongs. The RADIUS attributes for both users and groups are the same.
When RADIUS attributes are set for a group, the attribute is returned for each member of the group when they authenticate.
To define user-based RADIUS attributes, use either the SafeNet FreeRADIUS Agent or Microsoft NPS. Both the FreeRADIUS Agent and Microsoft NPS are capable of returning RADIUS attributes that are defined in SAS to the RADIUS client.
By default, RADIUS return attributes are defined for all Auth Nodes, or they can be restricted to selected auth nodes (excluding shared Auth Nodes) by using the Restrict To Auth Nodes check box.
When authenticating with a RADIUS token, SAS also passes RADIUS attributes to the RADIUS client that were received from an external RADIUS server. This is beneficial for authentication requests that may go to a third-party authentication service and then return through SAS. This is also useful for migrations where an external RADIUS server continues to authenticate users that are not yet migrated to SAS. With this feature, the RADIUS client can receive the same external attributes during the migration phase than before migration (without SAS).
Also, refer to Block RADIUS authentication.
SAS returns the attributes received from the external server after attributes that are configured in SAS. If the same attribute is configured in the external server and in SAS but with different values, it is up to the RADIUS client as to how this is interpreted. It is advised to avoid conflicting attribute definitions in SAS and the external RADIUS server.
Set RADIUS attributes for a user
-
On the SAS console, search for a user on the Assignment tab.
-
Select the user.
-
Click RADIUS Attributes (user).
-
Click Add.
The options and input values vary according to your selections. Consult your network equipment vendor’s documentation for guidance on which attributes to use.
-
Select Add.
-
Repeat as necessary to add more attributes.
Set RADIUS attributes for groups
-
On the SAS console, navigate to Groups > RADIUS Attribute (Group).
-
Select the group, and then select New.
The options and input values vary according to your selections. Consult your network equipment vendor’s documentation for guidance on which attributes to use.
-
Click Add.
-
Repeat as necessary to add more attributes.
View RADIUS attributes for a group
-
On the SAS console, select Groups > RADIUS Attribute (Group).
-
Select the group, and then select Search.
The attributes that are assigned to the group are listed.
-
To modify an attribute, click Edit, change the settings, and then click Save.
-
To remove the group attribute, click Remove and then click Remove to confirm.