I started a Security Group in our Directory and Resource Administration Server and called it ReadOnlyAccess. I want to map it to a group in ACS and give only read access to our switches. The thought is that putting a user in the ReadOnlyAccess group in DRA will dynamically put that user in the group in ACS thereby giving the user Read-Only access to our switches and routers. The problem is that when I make any changes to the group mapping in ACS it kicks every other user out of every other group, except ones that housed in the internal ACS database. I don't understand why because I am not changing the mapping for the read-write group. Can anyone help me with this?? I would greatly appreciate any words of advice.