<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP Identity Persistence in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857831#M1119</link>
    <description>&lt;P&gt;Thanks for the information Uriel! How does the console find PCs? For example, if a computer is re-imaged and first connects to a network that is&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; part of our domain, will the console reinstall the endpoint connector? I would imagine not (I would think the machine would need to be connected to our internal network), but I'm just trying to gain a better understanding of how identity persistence works or how/where it scans for PCs.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2019 19:18:17 GMT</pubDate>
    <dc:creator>ITandCoffee</dc:creator>
    <dc:date>2019-05-16T19:18:17Z</dc:date>
    <item>
      <title>AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857604#M1089</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;A couple of quick questions regarding identity persistence. When a computer is re-imaged and is not yet joined to our domain, will AMP still identify it using the MAC address and UUID to reinstall the endpoint connector? What about for remote computers that are not on our internal network, but running a VPN? What if their VPN is disabled and they are simply connected to the internet?&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857604#M1089</guid>
      <dc:creator>ITandCoffee</dc:creator>
      <dc:date>2020-02-21T05:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857701#M1105</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Hi,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Thanks for contacting Cisco Community, My name is Uriel Torres from the Advanced Threat Solutions team, You can configure identity persistence as the following.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="margin-left: .375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By policy across policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By MAC across policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By policy across business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By MAC across business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;I always recommend use:&lt;/P&gt;
&lt;UL style="margin-left: .375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By policy across the business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;By MAC across business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;For the first question, if you install AMP in a machine without the domain with the following and this configuration:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Hostname: Machine1&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Mac Address: 0e:12:5a:d7:15:11&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Identity persistence configuration: Identity persistence by hostname across the business.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Connector UUID: fac4e17e-bf66-4786-94ed-e63ed61033a6&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Then if you add the following domain: &lt;SPAN style="font-weight: bold;"&gt;example.com &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;You will have the following hostname: &lt;SPAN style="font-weight: bold;"&gt;Machine1.example.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Whit this configuration the information will be the following.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Hostname: Machine1.example.com&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Mac Address: 0e:12:5a:d7:15:11&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Identity persistence configuration: Identity persistence by hostname across business.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Connector UUID: e0857bde-2ce0-4ebd-8eb7-b32b52979c27&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;As you can see the UUID changes because the hostname has been changed, in this moment you will have 2 different machines registered on the cloud, if we look for a pattern the only concept that is the same is the MAC address, for this situation it will be better have "Identity Persistence By MAC across business"&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;With the same example of Machine 1 after adding the domain to the hostname even if the UUID changes the computer won't be duplicated because the MAC address will be the same.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;**********&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;About the second inquiry, you can install the AMP connector with a simple internet connection.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 16:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857701#M1105</guid>
      <dc:creator>jesutorr@cisco.com</dc:creator>
      <dc:date>2019-05-16T16:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857831#M1119</link>
      <description>&lt;P&gt;Thanks for the information Uriel! How does the console find PCs? For example, if a computer is re-imaged and first connects to a network that is&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; part of our domain, will the console reinstall the endpoint connector? I would imagine not (I would think the machine would need to be connected to our internal network), but I'm just trying to gain a better understanding of how identity persistence works or how/where it scans for PCs.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 19:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3857831#M1119</guid>
      <dc:creator>ITandCoffee</dc:creator>
      <dc:date>2019-05-16T19:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3866744#M1130</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/853121"&gt;@ITandCoffee&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;after the feature is enabled in the UI, you can choose how a system is identified again after re-imaging.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bildschirmfoto 2019-06-03 um 13.37.35.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/37939i54134CE349FC36A1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bildschirmfoto 2019-06-03 um 13.37.35.png" alt="Bildschirmfoto 2019-06-03 um 13.37.35.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here some more info how the settings are working (copied from the AMP help)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;None:&lt;/STRONG&gt; Connector logs are not synchronized with new Connector installs under any circumstance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;By MAC Address across Business:&lt;/STRONG&gt; New Connectors look for the most recent Connector that has the same MAC address to synchronize with across all policies in the business that have Identity Synchronization set to a value other than None&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;By MAC Address across Policy:&lt;/STRONG&gt; New Connectors look for the most recent Connector that has the same MAC address to synchronize with within the same policy.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;By Host name across Business:&lt;/STRONG&gt; New Connectors look for the most recent Connector that has the same host name to synchronize with across all policies in the business that have Identity Synchronization set to a value other than None.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;By Host name across Policy:&lt;/STRONG&gt; New Connectors look for the most recent Connector that has the same hostname to synchronize with within the same policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this gives you some better understanding into the feature.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 11:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/3866744#M1130</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2019-06-03T11:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/4022937#M1136</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To jump on this thread, I am having a similar issue but do not see the "Identity Persistence" option in the policy area, nor do i see an option to enable/disable it. Where can i check to see what identity persistence settings I have, and where can i go to change them?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 20:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/4022937#M1136</guid>
      <dc:creator>TylerFromPIH</dc:creator>
      <dc:date>2020-02-03T20:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Identity Persistence</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/4023511#M1140</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/997557"&gt;@TylerFromPIH&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;this feature is not enabled by default. You have to open a TAC case to enable the feature.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-identity-persistence/m-p/4023511#M1140</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2020-02-04T16:52:59Z</dc:date>
    </item>
  </channel>
</rss>

