<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE and Jamf Integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894404#M471274</link>
    <description>In the first video you sent the presenter never actually setup integration with ISE and Jamf, he built his own custom solution using the two APIs&lt;BR /&gt;&lt;BR /&gt;The second video you sent explains how the integration works, in theory, but certainly isn't a walkthrough of how to set it up.&lt;BR /&gt;&lt;BR /&gt;Is there any general documentation on how to integrate ISE with an MDM?</description>
    <pubDate>Sun, 21 Jul 2019 18:05:45 GMT</pubDate>
    <dc:creator>chris.schasse</dc:creator>
    <dc:date>2019-07-21T18:05:45Z</dc:date>
    <item>
      <title>Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894278#M471268</link>
      <description>&lt;P&gt;I'm integrating the latest version of Cisco ISE with the latest version of Jamf. Where is the best documentation on how to do this integration?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 02:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894278#M471268</guid>
      <dc:creator>chris.schasse</dc:creator>
      <dc:date>2019-07-21T02:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894282#M471272</link>
      <description>&lt;P&gt;Check out these videos:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.jamf.com/resources/videos/network-security-with-jamf-and-cisco/?keywords=ISE" target="_blank"&gt;Network Security with Jamf and Cisco&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.jamf.com/resources/videos/the-renaissance-of-nac-with-casper-suite-and-cisco-ise/?keywords=ISE" target="_blank"&gt;The Renaissance of NAC with Casper Suite and Cisco ISE&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 21 Jul 2019 03:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894282#M471272</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-21T03:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894404#M471274</link>
      <description>In the first video you sent the presenter never actually setup integration with ISE and Jamf, he built his own custom solution using the two APIs&lt;BR /&gt;&lt;BR /&gt;The second video you sent explains how the integration works, in theory, but certainly isn't a walkthrough of how to set it up.&lt;BR /&gt;&lt;BR /&gt;Is there any general documentation on how to integrate ISE with an MDM?</description>
      <pubDate>Sun, 21 Jul 2019 18:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894404#M471274</guid>
      <dc:creator>chris.schasse</dc:creator>
      <dc:date>2019-07-21T18:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894434#M471276</link>
      <description>&lt;P&gt;The basic configurations to integration ISE with an MDM have not changed much. So, the old docs are mostly applicable:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/BYOD_Advanced_Use_Case.html" target="_blank"&gt;Cisco Unified Access (UA) and Bring Your Own Device (BYOD) CVD - BYOD Advanced Use Case [Design Zone for Enterprise Networks] - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.jamf.com/9.9/casper-suite/administrator-guide/Network_Integration.html" target="_blank"&gt;Network Integration - Casper Suite Administrator's Guide | JAMF Software&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://www.jamf.com/jamf-nation/discussions/31165/cisco-ise-2-3-integration" target="_blank"&gt;Cisco ISE 2.3 Integration | Discussion | Jamf Nation&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-w-jamf-and-sccm-as-mdm/td-p/3714493" target="_blank"&gt;ISE w/ Jamf and SCCM as MDM - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/setting-up-ise-and-jamf-mdm/td-p/3552128" target="_blank"&gt;Solved: Setting up ISE and JAMF MDM? - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note that ISE 1.4 added support to allow multiple MDMs active. And, since 2.0 Patch 3 (or 1.4 Patch 8), ISE has been able to query for the MDM status of the endpoints that already registered in MDM but previously not known to ISE, by using a condition on&amp;nbsp;&lt;FONT face="comic sans ms,sans-serif"&gt;&lt;FONT color="#0000FF"&gt;MDM·MDMServerName&lt;/FONT&gt;&lt;/FONT&gt;. For example, given an authorization rule like below:&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;If&amp;nbsp;&lt;FONT color="#008080"&gt;MDM·MDMServerName&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#808080"&gt;Equals&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#800080"&gt;jamfDEMO&lt;/FONT&gt;&amp;nbsp;AND&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#008080"&gt;MDM·MDMServerReachable&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#808080"&gt;Equals&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#3366FF"&gt;Reachable&lt;/FONT&gt;&amp;nbsp;AND&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#008080"&gt;MDM·DeviceRegisterStatus&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#808080"&gt;Equals&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#3366FF"&gt;Registered&lt;/FONT&gt;&amp;nbsp;AND&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#008080"&gt;MDM·DeviceCompliantStatus&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#808080"&gt;Equals&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#3366FF"&gt;Compliant&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;then &lt;FONT color="#3366FF"&gt;PermitMDMCompliantAccess&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;where jamfDEMO is a MDM instance defined in ISE.&lt;/P&gt;
&lt;P&gt;ISE will query jamfDEMO for the status of the endpoint, if this rule is processed while evaluating for the endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 20:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894434#M471276</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-21T20:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894918#M471277</link>
      <description>I think I'm good on the instructions front, it looks pretty simple on ISE's side.&lt;BR /&gt;&lt;BR /&gt;However, what you said below brings up another question. We are trying to create a custom solution because we have multiple MDMs (InTune and Jamf). I know ISE supports multiple MDMs, but the issue we're running into is that the profiling engine in ISE isn't great at differentiating between types of Apple devices. All the iPhones should go to InTune, all the computers should go to Jamf.&lt;BR /&gt;&lt;BR /&gt;What it sounds like you're saying, however, is that if you setup this authorization rule, you could potentially have each MAC Address query BOTH MDMs for compliance? If so, that would save us a LOT of custom setup.</description>
      <pubDate>Mon, 22 Jul 2019 16:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3894918#M471277</guid>
      <dc:creator>chris.schasse</dc:creator>
      <dc:date>2019-07-22T16:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3895217#M471278</link>
      <description>&lt;BLOCKQUOTE&gt;What it sounds like you're saying, however, is that if you setup this authorization rule, you could potentially have each MAC Address query BOTH MDMs for compliance? If so, that would save us a LOT of custom setup.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I tried that and it did not work. Only the first occurrence of the ServerName conditions is used to trigger the queries. We need to find another attribute in the pre-condition to differentiate the endpoints. Potentially, endpoint profiles, endpoint logical profiles, endpoint groups, custom endpoint attributes, user groups, user attributes, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 00:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/3895217#M471278</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-23T00:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Jamf Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/4395594#M566994</link>
      <description>&lt;P&gt;In the above solution where you are building the AND conditions to include the MDM:MDMServerName field does that force the rest of them to use that particular MDM?&amp;nbsp; I'm trying to figure out how to use multiple MDMs since the conditions don't let you specify which one to use.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 16:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-jamf-integration/m-p/4395594#M566994</guid>
      <dc:creator>Steve Talbert</dc:creator>
      <dc:date>2021-04-29T16:00:55Z</dc:date>
    </item>
  </channel>
</rss>

