Views:
The Device Users screen provides the following actions:
  • Copy — Allows the user to select which devices receive a copy of the selected device users. This option is disabled when no users are selected or the user is not authorized to manage user accounts for devices. Use the following authentication guidelines when copying users:
    • Provide and confirm a password for users who require local authentication.
    • When you copy only users who use remote authentication, the New Password and Confirm Password fields are disabled. In addition, these users can only be copied to devices that support RADIUS or TACACS+ authentication. Devices that do not support RADIUS or TACACS+ are disabled in the device selector panel.
    • When you copy users who use local authentication mixed with users who authenticate remotely, only users who match the current authentication type configured for the device can be authenticated. For example, if the current authentication type is RADIUS, only RADIUS-authenticated users can be authenticated on the device. All devices are selectable and a password is required. The password is ignored for RADIUS and TACACS+ users that get copied to devices that support remote authentication servers. Attempts to copy RADIUS and TACACS+ users to a device that does not support these servers return a confirmation dialog, prompting you to confirm the action. If you decline, the operation is aborted. If you confirm the operation, the user is copied to the non-RADIUS device as a local user, and the password requirement applies.
  • Enable — Enables a user account for a specified device. A device user might be in a disabled state due to too many failed login attempts or a failure on the part of the user to perform a required password update.
  • New/Edit — Create or edit a user account for a specific device. Each device user consists of a User ID, password, the role performed by that device user, and the user’s authentication method. When creating a new device user the User ID field must be unique for the device. The User ID cannot be edited. Use the following authentication guidelines when creating or editing users:
    • If RADIUS or TACACS+ is selected as the authentication method for a new user, only devices that support those servers are selectable, and the New Password and Confirm Password fields are disabled. Only users who use local authentication require a password.
    • When editing multiple users across multiple devices, the preselected authentication method matches the authentication method of all the users if they authenticate in the same way.
    • When you edit users with a mix of authentication methods, a No Change authentication is preselected and an automatic password is generated. Changing the password will apply only to local users. Changing authentication from No Change to Local clears the automatic password and requires a new password. Changing authentication from No Change to RADIUS or TACACS+ impacts only devices that support those servers.
    • Delete — Delete the specific device users. Multiple device users can be deleted at the same time.
    • Refresh — Refresh all device user accounts. Refresh the device user accounts after you create or update a device user account.