<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Machine +User Auth for windows endpoint autheticating through IS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029227#M185737</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Paraq,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did you achieve this (AD domain AND the user is logged in using AD credentials) as I have same requirement. Could you please share your experience with me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My requirement is, I am xyz company employee having company laptop as well as my personal laptop. Both need to be authenticated through AD credentials but should go to different authorization profiles (company asset &amp;amp; non company asset). How to achieve this. Please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Awaiting for your positive &amp;amp; prompt response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 10 Nov 2012 20:33:44 GMT</pubDate>
    <dc:creator>Tabish Mirza</dc:creator>
    <dc:date>2012-11-10T20:33:44Z</dc:date>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029221#M185728</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;Is there any way to use machine + user auth at same time when authenticating Windows machine through ISE.&amp;nbsp; In Windows native supplicant there is option as &lt;/P&gt;&lt;P&gt;1) Machine OR user Auth&lt;/P&gt;&lt;P&gt;2) User Authentication &lt;/P&gt;&lt;P&gt;3) Machine Authentication &lt;/P&gt;&lt;P&gt;4) Guest authentication &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to give more priveledge access to endpoints where they are joined to AD domain AND the user is logged in using AD credentials. &lt;/P&gt;&lt;P&gt;Is there any way to achieve this functionality ...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029221#M185728</guid>
      <dc:creator>paragmahajan40</dc:creator>
      <dc:date>2019-03-11T02:26:44Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029222#M185729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With windows you do not have the option, however with ISE 1.1.1 and the latest cisco anyconnect nam supplicant (which is free) has a feature called eap chaining, it uses eap-fast to send the authentication sequence just as you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE release notes&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp307279"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp307279&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyconnect release notes&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/release/notes/anyconnect31rn.html#wp998871"&gt;http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/release/notes/anyconnect31rn.html#wp998871&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration of anyconnect - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/administration/guide/ac04namconfig.html#wp1065210"&gt;http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/administration/guide/ac04namconfig.html#wp1065210&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 22:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029222#M185729</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-21T22:33:42Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029223#M185730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is one way to achieve Machine+User authentication through ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prerequisites:&amp;nbsp; For windows 7 machine, please select “User or computer Authentication “ in authentication method ( Not applicable to Windows Xp)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to create two rules in Authorization policy as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st Rule&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;iselabin.local:ExternalGroups==Domain&amp;nbsp; Computers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the 1st rule , machine will get authorized access when machine boots up ( Before user enters his credentials)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd Rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Network Access:WasMachineAuthenticated ==True&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AND&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;iselabin.local:ExternalGroups==Domain Users&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User will enter credentials and he will get authorized access because of&amp;nbsp; 2nd Rule.Please find attached screenshot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it answers your query &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/3/2/99239-Machine%2BUser.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;P&gt;SecurView Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 07:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029223#M185730</guid>
      <dc:creator>neeleshus</dc:creator>
      <dc:date>2012-08-23T07:15:46Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029224#M185732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Neelesh. That is very helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 07:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029224#M185732</guid>
      <dc:creator>paragmahajan40</dc:creator>
      <dc:date>2012-08-23T07:22:43Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029225#M185733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tested solution what Neelesh has suggested.&amp;nbsp; I just want to confirm it is not related to MAR (Machine Access Restriction ).. I have enabled/disbaled MAR from ISE from external Identity source - AD -&amp;nbsp; advance setting. but it seems that MAR does not play any role for above authorization policies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on this...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 10:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029225#M185733</guid>
      <dc:creator>paragmahajan40</dc:creator>
      <dc:date>2012-09-05T10:41:37Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029226#M185735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a new feature in ise 1.1.1 and cisco anyconnect network access manager called eap chaining. What this does it allows you send both the machine and user authentication request in a single eap transaction. There is a new attribute called eapchaining and I am sure that will provide the results you are after. However, there is a bug that is open that will place you in a posturing loop, but if you are just performing authentication at the moment please take a look at this feature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp307279"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp307279&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 15:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029226#M185735</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T15:23:34Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029227#M185737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Paraq,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did you achieve this (AD domain AND the user is logged in using AD credentials) as I have same requirement. Could you please share your experience with me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My requirement is, I am xyz company employee having company laptop as well as my personal laptop. Both need to be authenticated through AD credentials but should go to different authorization profiles (company asset &amp;amp; non company asset). How to achieve this. Please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Awaiting for your positive &amp;amp; prompt response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Nov 2012 20:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029227#M185737</guid>
      <dc:creator>Tabish Mirza</dc:creator>
      <dc:date>2012-11-10T20:33:44Z</dc:date>
    </item>
    <item>
      <title>Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029228#M185739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as Tarik mentioned. With help of EAP-Chaining you can do this. There is a policy condition for this - EAP-Chaining machine succeeded, user suceeded which can match company assets and aditional rule can be machine failed, user succeeded which can go to different VLAN, ACL ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 23:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/2029228#M185739</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2012-11-12T23:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3916710#M185741</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For sure your procedure is working but there is a problem on it.&lt;/P&gt;&lt;P&gt;I have tested it.&lt;/P&gt;&lt;P&gt;During bootup,&amp;nbsp; let us says the Endpoint authenticates successfully (maybe through AD) and got temporary access.&lt;/P&gt;&lt;P&gt;After user credentials u got full access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When u are trying to a RDP with a local account which is allowed because it is a non domain user, you connect to local machine and you got Endpoint credentials because on RDP endpoint authentication information are sent to the ISE not USER.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to resolve that issue ? It is a serious problem !!!&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 13:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3916710#M185741</guid>
      <dc:creator>fogemarttt</dc:creator>
      <dc:date>2019-08-30T13:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Machine +User Auth for windows endpoint autheticating through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986667#M185743</link>
      <description>&lt;P&gt;Does the Windows native supplicant support EAP-TEAP? or will it be supported in a near future?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 15:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986667#M185743</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2019-11-20T15:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986897#M185744</link>
      <description>&lt;P&gt;Neelesh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will happen when user switches from Wired connection to Wireless connection, will ISE keep track of Machine authentication which happened over wired connection or does user need to log out and log back in every time they switch between wired and wireless connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 21:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986897#M185744</guid>
      <dc:creator>Nayan.Patel85</dc:creator>
      <dc:date>2019-11-20T21:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986919#M185745</link>
      <description>Traditionally the answer to this is no. ISE treats every Mac address as a unique endpoint. This is still the case if you are using native supplicants.&lt;BR /&gt;&lt;BR /&gt;The exception and why I said traditionally above is because as on ise 2.6 and any conne t 4.7 there is a concept of a UDI. The UDID remains the same for an endpoint regardless of Mac address.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Identify Managed Devices with Dynamic MAC Addresses&lt;BR /&gt;AnyConnect 4.7 now provides a Unique Device ID (UDID) to identify a connected user. The UDID value can be mapped with information from Mobile Device Management (MDM) providers to help identify users who have the same MAC address. MAC address sharing is common in open offices, where more than one person shares a dock or USB dongle.&lt;BR /&gt;&lt;BR /&gt;Business Outcome&lt;BR /&gt;You can develop a solution that uses the UDID to uniquely identify a user, when device connections are shared.</description>
      <pubDate>Wed, 20 Nov 2019 22:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3986919#M185745</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-11-20T22:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Machine +User Auth for windows endpoint autheticating through IS</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3995160#M185746</link>
      <description>&lt;P&gt;Hello Sir,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to confirm if the prerequisite is only windows 7 or it works with windows 10 machine also&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2019 00:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-user-auth-for-windows-endpoint-autheticating-through-ise/m-p/3995160#M185746</guid>
      <dc:creator>Kush</dc:creator>
      <dc:date>2019-12-07T00:04:21Z</dc:date>
    </item>
  </channel>
</rss>

