<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Easy Connect with trusted Domains in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3865122#M472615</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Yalbikaw&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thank you for your answer. It was very useful!&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2019 12:20:21 GMT</pubDate>
    <dc:creator>netcrackercorp</dc:creator>
    <dc:date>2019-05-30T12:20:21Z</dc:date>
    <item>
      <title>ISE Easy Connect with trusted Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3863710#M472605</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We are going to implement Easy Connect with Trusted Domains.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have groups from domain A and users from domain B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TEST USER tool shows that ISE goes to joint point which is domain A but cannot find an user, then it goes to domain B and pull information regarding user from there. Unfortunately there are no required groups in domain B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it normal behavior for ISE? Is it possible for ISE to understand that a group and user belong to different domains?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 13:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3863710#M472605</guid>
      <dc:creator>netcrackercorp</dc:creator>
      <dc:date>2019-05-28T13:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Easy Connect with trusted Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3864121#M472609</link>
      <description>I have asked the expert to take a look&lt;BR /&gt;</description>
      <pubDate>Tue, 28 May 2019 21:49:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3864121#M472609</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-28T21:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Easy Connect with trusted Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3864129#M472611</link>
      <description>&lt;P&gt;this situation is complex.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;because you are retrieving a domain local group for users in outside of this domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please check this document i believe it matches your scenario&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="topictitle2"&gt;Authorization Against an Active Directory Instance&lt;/H2&gt;
&lt;DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="section"&gt;&lt;A name="reference_77DFFA97638E4A6782C4BE7559463D95__section_46A12EA4E0F648B6BFD1A00FA4253B34" target="_blank"&gt;&lt;/A&gt;
&lt;P&gt;The following sections explain the mechanism that Cisco ISE uses to authorize a user or a machine against Active Directory.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="nested2" lang="en_US"&gt;&lt;A name="ID496" target="_blank"&gt;&lt;/A&gt;
&lt;H3 class="topictitle3"&gt;Active Directory Attribute and Group Retrieval for Use in Authorization Policies&lt;/H3&gt;
&lt;DIV&gt;
&lt;P&gt;&lt;A name="ID496__ID497" target="_blank"&gt;&lt;/A&gt;Cisco ISE retrieves user or machine attributes and groups from Active Directory for use in authorization policy rules. These attributes can be used in Cisco ISE policies and determine the authorization level for a user or machine. Cisco ISE retrieves user and machine Active Directory attributes after successful authentication and can also retrieve attributes for an authorization that is independent of authentication.&lt;/P&gt;
&lt;P&gt;&lt;A name="ID496__ID498" target="_blank"&gt;&lt;/A&gt; Cisco ISE may use groups in external identity stores to assign permissions to users or computers; for example, to map users to sponsor groups. You should note the following restrictions on group memberships in Active Directory:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A name="ID496__li_42DBC7FEB74F467B86AA794D5CFD4771" target="_blank"&gt;&lt;/A&gt;
&lt;P&gt;Policy rule conditions may reference any of the following: a user’s or computer’s primary group, the groups of which a user or computer is a direct member, or indirect (nested) groups.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A name="ID496__li_03DA80423BE34F07A3320603AF0F449B" target="_blank"&gt;&lt;/A&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;Domain local groups outside a user’s or computer’s account domain are not supported.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;from screenshots i can see they are domain local, if they were global things would have been different.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 22:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3864129#M472611</guid>
      <dc:creator>yalbikaw</dc:creator>
      <dc:date>2019-05-28T22:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Easy Connect with trusted Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3865122#M472615</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Yalbikaw&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thank you for your answer. It was very useful!&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 12:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3865122#M472615</guid>
      <dc:creator>netcrackercorp</dc:creator>
      <dc:date>2019-05-30T12:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Easy Connect with trusted Domains</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3869651#M472617</link>
      <description>&lt;P&gt;happy to hear that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 17:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easy-connect-with-trusted-domains/m-p/3869651#M472617</guid>
      <dc:creator>yalbikaw</dc:creator>
      <dc:date>2019-06-07T17:52:52Z</dc:date>
    </item>
  </channel>
</rss>

