<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE authentication policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884289#M471742</link>
    <description>Yes you could accomplish this in one device admin policy. Focus on your authz conditions. Quick example of how you could accomplish your requirement:&lt;BR /&gt;AD: External Groups Equals LOCATION1&lt;BR /&gt;AND&lt;BR /&gt;DEVICE-Device Type Equals LOCATION1 devices&lt;BR /&gt;Then push Shell profile containing read only&lt;BR /&gt;&lt;BR /&gt;Good luck &amp;amp; HTH!</description>
    <pubDate>Wed, 03 Jul 2019 19:47:52 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-07-03T19:47:52Z</dc:date>
    <item>
      <title>ISE authentication policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884272#M471741</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have five different locations for one of the client.&lt;/P&gt;&lt;P&gt;Each location is having 2 to 3 network device.&lt;/P&gt;&lt;P&gt;I want to give local site administrator the privilege to change their local device config only.&lt;/P&gt;&lt;P&gt;Also, one superadmin should be able to change the config on all site devices.&lt;/P&gt;&lt;P&gt;Is it possible to do it under one policy in Device admin policy set?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 19:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884272#M471741</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2019-07-03T19:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884289#M471742</link>
      <description>Yes you could accomplish this in one device admin policy. Focus on your authz conditions. Quick example of how you could accomplish your requirement:&lt;BR /&gt;AD: External Groups Equals LOCATION1&lt;BR /&gt;AND&lt;BR /&gt;DEVICE-Device Type Equals LOCATION1 devices&lt;BR /&gt;Then push Shell profile containing read only&lt;BR /&gt;&lt;BR /&gt;Good luck &amp;amp; HTH!</description>
      <pubDate>Wed, 03 Jul 2019 19:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884289#M471742</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-07-03T19:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884487#M471743</link>
      <description>Absolutely possible. Your devices should be in separate NDGs. Then create a&lt;BR /&gt;policy to match the NDG with AD group (if they are AD users) and assign&lt;BR /&gt;authorization rules. I am assuming that you have them in separate AD group&lt;BR /&gt;or you can use any other form of separation between the users (username for&lt;BR /&gt;example).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Jul 2019 05:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3884487#M471743</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-07-04T05:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3891412#M471744</link>
      <description>&lt;P&gt;I configured a Device type which contained the main group for that Client.&lt;/P&gt;&lt;P&gt;Also configured device groups for different sites. e.g. 5 groups for 5 sites.&lt;/P&gt;&lt;P&gt;Then I configured a policy in policy sets so that it will match All devices for that client.&lt;/P&gt;&lt;P&gt;After that, I configured authorization policy and in the condition, I used logical AND of site_1 and internal user.&lt;/P&gt;&lt;P&gt;This did the trick for me.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 23:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-policy/m-p/3891412#M471744</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2019-07-16T23:03:30Z</dc:date>
    </item>
  </channel>
</rss>

