<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Authz for AC 4.7 UDID in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864291#M472614</link>
    <description>&lt;P&gt;Hi Jason,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, is this PhoneID exposed via ISE API or PxGrid Session Object?&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;
&lt;P&gt;V.Venkata Manikandan&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 07:32:38 GMT</pubDate>
    <dc:creator>VVVENKAT</dc:creator>
    <dc:date>2019-05-29T07:32:38Z</dc:date>
    <item>
      <title>ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3863753#M472603</link>
      <description>&lt;P&gt;With AnyConnect 4.7 sending UDID to ISE, one of my customer would like to use the same in AuthZ condition and check against SQL db before granting complete access. The UDID is sent as "PhoneID" by AnyConnect. Just wanted to confirm if I can create a custom user attribute with internal name as PhoneID and write an AuthZ to check the value against SQL db.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;
&lt;P&gt;V.Venkata Manikandan&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 10:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3863753#M472603</guid>
      <dc:creator>VVVENKAT</dc:creator>
      <dc:date>2019-05-28T10:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864125#M472608</link>
      <description>I don’t think this is possible but will check with the SME&lt;BR /&gt;</description>
      <pubDate>Tue, 28 May 2019 21:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864125#M472608</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-28T21:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864149#M472612</link>
      <description>&lt;P&gt;Thanks Jason. Will wait for the response.&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;
&lt;P&gt;V.Venkata Manikandan&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 23:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864149#M472612</guid>
      <dc:creator>VVVENKAT</dc:creator>
      <dc:date>2019-05-28T23:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864291#M472614</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, is this PhoneID exposed via ISE API or PxGrid Session Object?&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;
&lt;P&gt;V.Venkata Manikandan&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 07:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3864291#M472614</guid>
      <dc:creator>VVVENKAT</dc:creator>
      <dc:date>2019-05-29T07:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3866856#M472672</link>
      <description>&lt;P&gt;UDID is not exposed via API.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, regarding your initial query , as Jason mentioned, you cannot use the UDID attribute in Authz profile today.&lt;/P&gt;
&lt;P&gt;The use use case we support today is with Posture condition wherein we can manually add the UDID to AD attribute and use it to get compliance information from AD.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 14:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/3866856#M472672</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2019-06-03T14:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4432564#M568427</link>
      <description>&lt;P&gt;Hi Nidhi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got a customer looking to use the UDID in the posture condition. Do you have a working example of how this is done as you stated above?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 19:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4432564#M568427</guid>
      <dc:creator>toyip</dc:creator>
      <dc:date>2021-07-13T19:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4432661#M568430</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/469160"&gt;@toyip&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;I haven't tried the following yet, but it's worth a shot ...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;AD&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;. insert the &lt;STRONG&gt;UDID&lt;/STRONG&gt; in the &lt;U&gt;&lt;EM&gt;description&lt;/EM&gt;&lt;/U&gt; field (fo ex.:) of an user.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;ISE&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;. &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt;&lt;/STRONG&gt; &lt;U&gt;select your AD&lt;/U&gt;, at &lt;STRONG&gt;Attributes&lt;/STRONG&gt; tab, select an attribute from &lt;STRONG&gt;AD&lt;/STRONG&gt; (for ex.: &lt;U&gt;&lt;EM&gt;description&lt;/EM&gt;&lt;/U&gt;)&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;. &lt;STRONG&gt;Policy &amp;gt; Policy Sets &amp;gt;&lt;/STRONG&gt; select you policy &lt;STRONG&gt;&amp;gt; Authorization Policy&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; - &lt;U&gt;Condition&lt;/U&gt;:&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Cisco.cisco-av-pair&lt;/STRONG&gt; &lt;U&gt;CONTAINS&lt;/U&gt; &lt;STRONG&gt;&lt;EM&gt;&amp;lt;your AD&amp;gt;.description&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: in this case the &lt;STRONG&gt;Cisco.cisco-av-pair&lt;/STRONG&gt; has the &lt;STRONG&gt;UDID&lt;/STRONG&gt; of the user.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 23:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4432661#M568430</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-07-13T23:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4433179#M568458</link>
      <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply. I thought the UDID was part of a posture condition as suggested by the other folks in this thread. But your suggestion says otherwise (no posturing involved). I've been looking at the posture conditions in a lab, but not seeing how you can use the UDID in it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To clarify, the UDID has to be added in AD itself, then ISE picks it up as an AD attribute. Is that correct?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 16:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4433179#M568458</guid>
      <dc:creator>toyip</dc:creator>
      <dc:date>2021-07-14T16:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authz for AC 4.7 UDID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4433240#M568460</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/469160"&gt;@toyip&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;that's correct.&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;UDID&lt;/STRONG&gt; has to be added in &lt;STRONG&gt;AD&lt;/STRONG&gt; itself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Note: just like adding a &lt;STRONG&gt;IP Telephone&amp;nbsp;Number&lt;/STRONG&gt; on the &lt;STRONG&gt;AD&lt;/STRONG&gt; (for example: using the&amp;nbsp;&lt;U&gt;&lt;EM&gt;ipPhone&lt;/EM&gt;&lt;/U&gt; attribute)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 18:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authz-for-ac-4-7-udid/m-p/4433240#M568460</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-07-14T18:15:04Z</dc:date>
    </item>
  </channel>
</rss>

