<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE best practice for computer authentication question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899336#M470967</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I am in the process of deploying ISE at a company.&amp;nbsp; The question is focused on wired authentication for AD joined computers.&lt;/P&gt;&lt;P&gt;Is there a benefit of doing authorization using certificates vs ISE checking if the computer is in a particular AD group e.g. Domain computers?&lt;/P&gt;&lt;P&gt;I am on ISE 2.4 Patch 9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jul 2019 14:39:41 GMT</pubDate>
    <dc:creator>BrianPersaud</dc:creator>
    <dc:date>2019-07-29T14:39:41Z</dc:date>
    <item>
      <title>ISE best practice for computer authentication question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899336#M470967</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I am in the process of deploying ISE at a company.&amp;nbsp; The question is focused on wired authentication for AD joined computers.&lt;/P&gt;&lt;P&gt;Is there a benefit of doing authorization using certificates vs ISE checking if the computer is in a particular AD group e.g. Domain computers?&lt;/P&gt;&lt;P&gt;I am on ISE 2.4 Patch 9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 14:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899336#M470967</guid>
      <dc:creator>BrianPersaud</dc:creator>
      <dc:date>2019-07-29T14:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE best practice for computer authentication question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899434#M470968</link>
      <description>&lt;P&gt;Some benefits of cert-based auth are&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;AD replications on password changes could be slow&lt;/LI&gt;
&lt;LI&gt;Password authentication might not be allowed; e.g. Microsoft Windows Defender Credential Guard&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Jul 2019 17:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899434#M470968</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-29T17:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE best practice for computer authentication question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899682#M470969</link>
      <description>You can still check group membership or AD attributes of machines when doing certificate authentication.  It is common to leverage one or the other to provide differentiated access while doing machine certificate auth.  &lt;BR /&gt;&lt;BR /&gt;Taking it a step further you could also leverage AnyConnect NAM with eap-chaining, authenticating both the machine and user at the same time.  &lt;BR /&gt;&lt;BR /&gt;It really comes down to the unique requirements of the deployment, no one is the same and there are many valid methods.</description>
      <pubDate>Tue, 30 Jul 2019 02:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-best-practice-for-computer-authentication-question/m-p/3899682#M470969</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-30T02:49:15Z</dc:date>
    </item>
  </channel>
</rss>

