<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Set wrapper Creation with user AD group name in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836571#M473942</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I don't see how this will work. Technically you can read AD group before&lt;BR /&gt;authenticating the user successfully to get its attribute&lt;BR /&gt;</description>
    <pubDate>Thu, 11 Apr 2019 06:53:33 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2019-04-11T06:53:33Z</dc:date>
    <item>
      <title>Policy Set wrapper Creation with user AD group name</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836531#M473935</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;One of my customers wants to create Policy Set with condition of user AD group (at cover of policy set), however, i don't see option to select the AD group name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any idea if we will support in upcoming releases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jay&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 05:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836531#M473935</guid>
      <dc:creator>Jay Tiwari</dc:creator>
      <dc:date>2019-04-11T05:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set wrapper Creation with user AD group name</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836534#M473939</link>
      <description>&lt;P&gt;While I understand the requirement, I doubt ISE would do this, since it is non sensical because authentication has not yet taken place. In the Policy Set Conditions were are checking the radius attributes for hints about the type of authentication (e.g. Service-Type, etc) and who is making the request (e.g. NDG which is basically checking the source IP of the request ). Even if ISE had the ability to check AD Group, you would first need to have passed authentication in order to care about the users AD attributes and groups. It would be very CPU intensive to perform this check for every radius request prior to the authentication stage.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AD Group checks are generally done during Authorization because it makes sense to do it here. Why does this not meet the customer’s needs?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 05:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836534#M473939</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-04-11T05:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set wrapper Creation with user AD group name</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836571#M473942</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I don't see how this will work. Technically you can read AD group before&lt;BR /&gt;authenticating the user successfully to get its attribute&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Apr 2019 06:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836571#M473942</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-04-11T06:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set wrapper Creation with user AD group name</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836686#M473945</link>
      <description>I don’t get your response. Authentication simply checks if the credentials are valid and then continues onto authorization</description>
      <pubDate>Thu, 11 Apr 2019 10:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-wrapper-creation-with-user-ad-group-name/m-p/3836686#M473945</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-11T10:22:02Z</dc:date>
    </item>
  </channel>
</rss>

