<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3929908#M456884</link>
    <description>&lt;P&gt;For my ISE deployment, i want to use certificate-based authentication for all my Windows machines&amp;nbsp; By default, certificate-based authentication does not check the certificate against Active Directory, or requires credentials from the user. This essentially means that no groups are returned as part of the authentication request. what can i do in order the user be authorized based on Active Directory group membership?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2019 07:22:31 GMT</pubDate>
    <dc:creator>henokk601</dc:creator>
    <dc:date>2019-09-25T07:22:31Z</dc:date>
    <item>
      <title>ISE Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3929908#M456884</link>
      <description>&lt;P&gt;For my ISE deployment, i want to use certificate-based authentication for all my Windows machines&amp;nbsp; By default, certificate-based authentication does not check the certificate against Active Directory, or requires credentials from the user. This essentially means that no groups are returned as part of the authentication request. what can i do in order the user be authorized based on Active Directory group membership?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 07:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3929908#M456884</guid>
      <dc:creator>henokk601</dc:creator>
      <dc:date>2019-09-25T07:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3931214#M456886</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/234014"&gt;@henokk601&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In EAP-TLS authentication you create a CAP (Certificate Authentication Profile) and this determines what ISE will do with the client cert that is presented by the supplicant (Windows PS in your case).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can do things like extract the Subject CN (Common Name) from the client cert and then have it looked up in AD to see whether that AD Account is active/exists etc.&amp;nbsp; Furthermore, when you do that, you can then use the AD Groups and Attributes returned from the AD lookup in your ISE Authorization Profiles to check whether that AD Account is a member of xyz Security Group or whatever else you want to check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 05:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3931214#M456886</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-09-27T05:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3931585#M456888</link>
      <description>&lt;P&gt;It sounds like you are you trying to authenticate just your computers via eap-tls and utilize AD sec groups to push Authz policy.&amp;nbsp; However, if you intend on incorporating auth for both users and computers you will need to focus efforts on using NAM for eap-chaining.&amp;nbsp; IMO using native supplicant is typically easier to use, and manage.&amp;nbsp; If you are simply doing computer auth only focus on what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;mentioned as he shared valuable comments.&amp;nbsp; Also, keep in mind that you can deploy native supplicant configuration via GPOs.&amp;nbsp; Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 16:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment/m-p/3931585#M456888</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-09-27T16:19:32Z</dc:date>
    </item>
  </channel>
</rss>

