Hi
One of the news in ClearPass 6.11 is the option to configure multiple TACACS+ server addresses instead of just one.
The TACACS+ server must send the correct attributes back to ClearPass, compare with the standard enforcement profiles for administrative login i.e. [TACACS Super Admin].
If you have custom admin privileges you have to return the matching names.
Yes, local authentication is still working. In the use case where I have utilized this it has been good. As a service provider I send authentications back to uor ClearPass, but sometimes local technicians within the customer network must be able to authenticate as well to get a read only role in ClearPass.
But I agree, it could be an option at least to not allow local authentication as long as the TACACS server is available
I have only tested to utilize this to other ClearPass servers and not with 2FA/MFA scenarios.
For Admin logon with smart card I have integrated with ADFS or utilized ClearPass as the IdP for SAML authentication.
If you have smart card this may be the easiest way to get 2FA/MFA.
------------------------------
Best Regards
Jonas Hammarbäck
MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------