<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local Users (belongs to domain) on ISE cannot derive Password from Windows Database in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323378#M135212</link>
    <description>&lt;P&gt;Dear Support Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are in the progress of Migrating ACS4.2 to ISE3355 running 1.1.4. We have SSL VPN Users &amp;amp; Wireless Users to be migrated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.1.4 is already integrated with AD Windows 2008 and can see all the groups defined on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: in ACS 4.x &amp;amp; even 5.x, we have option to add a user locally (users belonging to domain) , and&amp;nbsp; we can configure user’s password to be derived from Windows Database. It helps to control AAA Policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also helps to avoid configuring "users" in specific groups on AD and as a result no dependency on System Team to configure users in specific groups, which can be used in policy making on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;However while doing the same, I could not find an option in ISE 1.1.4. Password cannot be derived from windows database. Password has to be set manually&lt;/SPAN&gt;, that clearly means that i have to arrange the users in specific group on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a platform specific issue or am I missing something ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your valuable time to look into this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahad....&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:44:53 GMT</pubDate>
    <dc:creator>MANSOORQ123</dc:creator>
    <dc:date>2019-03-11T03:44:53Z</dc:date>
    <item>
      <title>Local Users (belongs to domain) on ISE cannot derive Password from Windows Database</title>
      <link>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323378#M135212</link>
      <description>&lt;P&gt;Dear Support Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are in the progress of Migrating ACS4.2 to ISE3355 running 1.1.4. We have SSL VPN Users &amp;amp; Wireless Users to be migrated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.1.4 is already integrated with AD Windows 2008 and can see all the groups defined on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: in ACS 4.x &amp;amp; even 5.x, we have option to add a user locally (users belonging to domain) , and&amp;nbsp; we can configure user’s password to be derived from Windows Database. It helps to control AAA Policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also helps to avoid configuring "users" in specific groups on AD and as a result no dependency on System Team to configure users in specific groups, which can be used in policy making on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;However while doing the same, I could not find an option in ISE 1.1.4. Password cannot be derived from windows database. Password has to be set manually&lt;/SPAN&gt;, that clearly means that i have to arrange the users in specific group on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a platform specific issue or am I missing something ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your valuable time to look into this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahad....&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323378#M135212</guid>
      <dc:creator>MANSOORQ123</dc:creator>
      <dc:date>2019-03-11T03:44:53Z</dc:date>
    </item>
    <item>
      <title>Local Users (belongs to domain) on ISE cannot derive Password fr</title>
      <link>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323379#M135261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It seems that i have to open a TAC case to get cisco official explanation on this feature, it was a nice feature, which has been unnecessarily deprecated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Inputs from anyone, who has similiar requirement, Please share it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 08:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323379#M135261</guid>
      <dc:creator>MANSOORQ123</dc:creator>
      <dc:date>2013-08-08T08:04:05Z</dc:date>
    </item>
    <item>
      <title>Local Users (belongs to domain) on ISE cannot derive Password fr</title>
      <link>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323380#M135280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE: Using Internal Identity User can gain access to Admin Dashboard &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This fix addresses the issue where internal users gain access to the Cisco ISE Admin portal Home page when they are not mapped to any Cisco ISE administrator group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 19:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-users-belongs-to-domain-on-ise-cannot-derive-password-from/m-p/2323380#M135280</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-08-14T19:10:23Z</dc:date>
    </item>
  </channel>
</rss>

