<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE And local Machine Access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-local-machine-access/m-p/3052210#M22750</link>
    <description>&lt;P&gt;Hellow guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I created policies for Machine and user authentication under ISE, so if the machine and user is AD authenticated, then Authorization profile will be applied.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question, if the Machine AD authenticated but the user is using local account to access, i want this user to have specific access, not deny.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How can i acheive this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:44:23 GMT</pubDate>
    <dc:creator>network@bigbenkuwait.com</dc:creator>
    <dc:date>2019-03-11T07:44:23Z</dc:date>
    <item>
      <title>ISE And local Machine Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-local-machine-access/m-p/3052210#M22750</link>
      <description>&lt;P&gt;Hellow guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I created policies for Machine and user authentication under ISE, so if the machine and user is AD authenticated, then Authorization profile will be applied.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question, if the Machine AD authenticated but the user is using local account to access, i want this user to have specific access, not deny.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How can i acheive this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-local-machine-access/m-p/3052210#M22750</guid>
      <dc:creator>network@bigbenkuwait.com</dc:creator>
      <dc:date>2019-03-11T07:44:23Z</dc:date>
    </item>
    <item>
      <title>It's not exactly what you</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-local-machine-access/m-p/3052211#M22751</link>
      <description>&lt;P&gt;It's not exactly what you asked for but this might work:&lt;/P&gt;
&lt;P&gt;Copy the first AuthC result (machine and user is from AD identity source) to a second one without the user check. Since the AuthC results are evaluated top down with first match ending the processing, the second one will only be checked where there is a machine authentication but no user authentication (at least not on any identity store that ISE know about).&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 10:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-local-machine-access/m-p/3052211#M22751</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-24T10:41:55Z</dc:date>
    </item>
  </channel>
</rss>

