<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Single PC restriction for Windows Login in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712367#M492404</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally when a user is added in the domain, the user is added in a way he can login to any of the computers in the domain. I have a specific use case in which the domain admin wants to restrict a user to login specifically to only one PC. The moment this restriction is made in the AD, the ISE authentication fails for this user. I have tried allowing the user to access this particular PC as well as ISE, however that also didn't succeed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea, when ISE sends the auth requests to the AD,&amp;nbsp; how does the AD consider this request. Does the AD consider the user to login to the PC/ISE/switch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Nikhil&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 18:56:35 GMT</pubDate>
    <dc:creator>nikhilcherian</dc:creator>
    <dc:date>2018-09-24T18:56:35Z</dc:date>
    <item>
      <title>Single PC restriction for Windows Login</title>
      <link>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712367#M492404</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally when a user is added in the domain, the user is added in a way he can login to any of the computers in the domain. I have a specific use case in which the domain admin wants to restrict a user to login specifically to only one PC. The moment this restriction is made in the AD, the ISE authentication fails for this user. I have tried allowing the user to access this particular PC as well as ISE, however that also didn't succeed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea, when ISE sends the auth requests to the AD,&amp;nbsp; how does the AD consider this request. Does the AD consider the user to login to the PC/ISE/switch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Nikhil&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 18:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712367#M492404</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-09-24T18:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Single PC restriction for Windows Login</title>
      <link>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712408#M492406</link>
      <description>&lt;P&gt;If you add the ISE PSN computer accounts in AD to the logon to workstation restrictions that should allow their account to work.&amp;nbsp; You are saying that doesn't work?&amp;nbsp; You could also switch ISE to using LDAP to AD which shouldn't trigger a logon to workstation restriction.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 19:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712408#M492406</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-24T19:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Single PC restriction for Windows Login</title>
      <link>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712966#M492409</link>
      <description>&lt;P&gt;Just to add to what Paul mentioned. When ISE is integrated with AD,&amp;nbsp;each ISE node become a computer object in the domain. When user authenticates via 802.1X, user is essentially logging on to the ISE node (Which considers to be logging on locally in terms of Windows user rights). Since PSN persona processes the authentication requests, you should add all of the PSNs to the allowed computer list for a give user along with one's Windows PC.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 16:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3712966#M492409</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-09-25T16:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Single PC restriction for Windows Login</title>
      <link>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3713015#M492410</link>
      <description>&lt;P&gt;I will double check this with the AD team &amp;amp; confirm if they have added all the ISE Nodes to the allowed list&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 17:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-pc-restriction-for-windows-login/m-p/3713015#M492410</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-09-25T17:58:00Z</dc:date>
    </item>
  </channel>
</rss>

