<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE AD Attribute Not Pulling. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482178#M499415</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, MS permissions can be set per object. Thus, ISE might not have the same permissions to users in the same domain and same groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2018 13:23:49 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-06-08T13:23:49Z</dc:date>
    <item>
      <title>ISE AD Attribute Not Pulling.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482175#M499412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Policy set for Anyconnect Via RADIUS, which looks at the Dial-in attribute for AD. for some reason this is only being pulled for some users and not others. All the user are under the same Domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 19:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482175#M499412</guid>
      <dc:creator>Jordan Taylor</dc:creator>
      <dc:date>2018-06-06T19:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Attribute Not Pulling.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482176#M499413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems the ISE computer account in AD not having read permissions for such attribute in some particular AD user objects.&lt;/P&gt;&lt;P&gt;You might want to try allowing "Read All Properties" for ISE. If that not possible, then&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 15px;"&gt;use auditing to see what permissions you need (by looking at what accesses fail in the audit log).&amp;nbsp; Repeat until it all seems to work.&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: 'Segoe UI', sans-serif; font-size: 10pt;"&gt;References:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 'Segoe UI', sans-serif;"&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/aa706028(v=vs.85).aspx" style="color: purple; text-decoration: underline;"&gt;How Access Control Works in Active Directory Domain Services&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 'Segoe UI', sans-serif;"&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/ms675745(v=vs.85).aspx" style="color: purple; text-decoration: underline;"&gt;Controlling Access to Objects and Their Properties&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 'Segoe UI', sans-serif;"&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/ms677958(v=vs.85).aspx" style="color: purple; text-decoration: underline;"&gt;Setting Rights to Specific Types of Objects&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 'Segoe UI', sans-serif;"&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/ms677957(v=vs.85).aspx" style="color: purple; text-decoration: underline;"&gt;Setting Rights to Specific Properties of Specific Types of Objects&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;

&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 23:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482176#M499413</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-06T23:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Attribute Not Pulling.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482177#M499414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would this still apply when I can pull the attribute need from some users over others? And these users are in the same Domain same groups. and I still get the same behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 13:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482177#M499414</guid>
      <dc:creator>Jordan Taylor</dc:creator>
      <dc:date>2018-06-08T13:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Attribute Not Pulling.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482178#M499415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, MS permissions can be set per object. Thus, ISE might not have the same permissions to users in the same domain and same groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 13:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482178#M499415</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-08T13:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE AD Attribute Not Pulling.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482179#M499416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, are there any best practice pages on Active Directory architecture. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found this one. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html#task_E34DC84405014271B33F6D4E455A441D" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html#task_E34DC84405014271B33F6D4E455A441D"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html#tas…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2018 03:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-attribute-not-pulling/m-p/3482179#M499416</guid>
      <dc:creator>Jordan Taylor</dc:creator>
      <dc:date>2018-06-09T03:48:50Z</dc:date>
    </item>
  </channel>
</rss>

