<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple &amp;quot;MemberOf&amp;quot; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122050#M156518</link>
    <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would ISE deal with an user that has multiple entries for "memberOf"for group assignment?&amp;nbsp; Would ISE use the 1st MemberOf value it encounter to assign a group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:54:02 GMT</pubDate>
    <dc:creator>cpaquet</dc:creator>
    <dc:date>2019-03-11T02:54:02Z</dc:date>
    <item>
      <title>Multiple "MemberOf"</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122050#M156518</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would ISE deal with an user that has multiple entries for "memberOf"for group assignment?&amp;nbsp; Would ISE use the 1st MemberOf value it encounter to assign a group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122050#M156518</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2019-03-11T02:54:02Z</dc:date>
    </item>
    <item>
      <title>Multiple "MemberOf"</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122051#M156553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cath-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE will "read" the groups in the order that you have configured them in your authorization rules. So I would recommend that you place the more specific groups towards the bottom and the most common groups towards the bottom. For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IF member of &lt;STRONG&gt;executives &lt;/STRONG&gt;then authorization profile &lt;STRONG&gt;executives_users&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IF member of &lt;STRONG&gt;domain users &lt;/STRONG&gt;then authorization profile &lt;STRONG&gt;regular_users&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 04:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122051#M156553</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-12-18T04:08:20Z</dc:date>
    </item>
    <item>
      <title>Multiple "MemberOf"</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122052#M156580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Neno.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please clarify your suggestion "...I would recommend that you place the more specific groups towards the bottom and the most common groups towards the bottom".&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mean placing the specific at the top and the generic at the bottom, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 12:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122052#M156580</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2012-12-18T12:02:34Z</dc:date>
    </item>
    <item>
      <title>Multiple "MemberOf"</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122053#M156603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that was a typo on my end &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; You want generic towards the bottom and specific towards the top. Think of it that way: Everyone is part of "domain users" so everyone would match that rule but not everyone would be a member of the "executives" so you would want the executives group to be above the domain users&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2012 00:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122053#M156603</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-12-19T00:48:28Z</dc:date>
    </item>
    <item>
      <title>Multiple "MemberOf"</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122054#M156647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Neno for all your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;cath.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2012 12:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-quot-memberof-quot/m-p/2122054#M156647</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2012-12-19T12:38:30Z</dc:date>
    </item>
  </channel>
</rss>

