<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE SCCM DDM endpoint registration check for user session in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3722371#M507503</link>
    <description>&lt;P&gt;Glad it worked !&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 04:30:41 GMT</pubDate>
    <dc:creator>Nidhi</dc:creator>
    <dc:date>2018-10-10T04:30:41Z</dc:date>
    <item>
      <title>ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3709999#M507488</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't found any good information detailing how ISE queries SCCM when integrated as a Desktop Device Manager.&lt;/P&gt;
&lt;P&gt;I assume that ISE uses the Windows machine hostname as the identity for the query (WMI/API?) against SCCM to request Registration/Compliance status. Is there any documentation available that defines this in more detail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a PEAP or EAP-TLS user auth session, is ISE still able to query SCCM for the Registration/Compliance status of the related machine (assuming native supplicant with no EAP-Chaining)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 23:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3709999#M507488</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-09-19T23:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3710003#M507490</link>
      <description>EAP chaining is not required&lt;BR /&gt;&lt;BR /&gt;I believe a special registration id is setup between the agent ise and the server&lt;BR /&gt;&lt;BR /&gt;Also the integration is special between Microsoft sccm and ise for a more tight package and easier streamlined on boarding&lt;BR /&gt;&lt;BR /&gt;Have you checked this out?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-design-amp-integration-guides/ta-p/3621164#toc-hId--881615321" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-design-amp-integration-guides/ta-p/3621164#toc-hId--881615321&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Sep 2018 00:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3710003#M507490</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-20T00:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3711791#M507493</link>
      <description>&lt;P&gt;Thanks Jason. I've seen that PPT deck, but it's still pretty vague about the WMI comms between ISE and SCCM.&lt;/P&gt;
&lt;P&gt;I was hoping we would have something with a bit more detail on what identity ISE uses in the WMI call (similar to MDM API call using MAC Address) so I could be sure that an SCCM registration check will work on a User Auth session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've setup SCCM in my home lab so I'll do some testing when I have a chance and update this post with my results.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Sep 2018 22:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3711791#M507493</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-09-23T22:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3712243#M507496</link>
      <description>&lt;P&gt;i asked our SME &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/359830"&gt;@Nidhi&lt;/a&gt;to take a look&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 18:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3712243#M507496</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-24T18:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3712899#M507498</link>
      <description>&lt;P&gt;ISE uses&amp;nbsp; user account which is member of SMS admin group to query the status of endpoints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sample query looks like this -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;select SMS_R_System.Name, SMS_G_System_CI_ComplianceState.CI_UniqueID, SMS_G_System_CI_ComplianceState.ComplianceState, SMS_G_System_CI_ComplianceState.LocalizedDisplayName, SMS_G_System_CH_ClientSummary.LastPolicyRequest from SMS_R_System left join SMS_G_System_CI_ComplianceState on SMS_G_System_CI_ComplianceState.ResourceID = SMS_R_System.ResourceId left join SMS_G_System_CH_ClientSummary on SMS_G_System_CH_ClientSummary.ResourceID = SMS_R_System.ResourceId left join SMS_G_System_NETWORK_ADAPTER on SMS_G_System_NETWORK_ADAPTER.ResourceId = SMS_R_System.ResourceId where (SMS_R_System.MacAddresses like ‘%MAC_ADDRESS%' OR SMS_G_System_NETWORK_ADAPTER.MACAddress like ‘%MAC_ADDRESS%') AND SMS_G_System_CI_ComplianceState.CI_UniqueID='ScopeId_5E0BA349-421B-4663-8E5F-3D2C408A3FA5/Baseline_28ff969f-cc82-4246-a15d-214d1489b076’&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;\&lt;/P&gt;
&lt;P&gt;I am also in the process of documenting the details for the MDM flow and should be available in few days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3712899#M507498</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-09-25T15:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3713133#M507500</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/359830"&gt;@Nidhi&lt;/a&gt; and &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can also include information on what constitutes a 'MDM.DeviceRegisterStatus=true' response from SCCM, that would be helpful.&lt;/P&gt;
&lt;P&gt;In my home lab, I've performed a manual device discovery in SCCM for my test PC which includes the MAC Address but I still appear to be getting a 'MDM.DeviceRegisterStatus=false' response from SCCM. I don't currently have the SCCM Client deployed to the PC, but I'm not sure if that's required.&lt;/P&gt;
&lt;P&gt;I would like to get some of this sorted out prior to trying to setup a PoC in my customer's environment.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 21:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3713133#M507500</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-09-25T21:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3722283#M507502</link>
      <description>&lt;P&gt;Just to close the loop on this, I was able to get this working in my lab with the following caveats/observations.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;SCCM does not consider the endpoint registered until the CM Client is installed and Active (PC calls home to SCCM). Manually registering an endpoint in SCCM (and adding the MAC address) does not work as SCCM returns a 'MDM.DeviceRegisterStatus=false' response.&lt;/LI&gt;
&lt;LI&gt;The SCCM registration check works for both 802.1x computer and user sessions (user or computer auth setting in Windows)&lt;/LI&gt;
&lt;LI&gt;The SCCM registration check works for both Wired and Wireless sessions. I would have to assume that the CM Client communicates all available MAC Addresses to SCCM (unlike other MDM vendors like JAMF, AirWatch, etc).&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 10 Oct 2018 01:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3722283#M507502</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-10-10T01:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3722371#M507503</link>
      <description>&lt;P&gt;Glad it worked !&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 04:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/3722371#M507503</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-10-10T04:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4133821#M562269</link>
      <description>&lt;P&gt;HI Greg,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tks for your information. Could you please help with my doubt?&lt;/P&gt;&lt;P&gt;The SCCM/MDM I check the rules before or after the Anyconnect posture?&amp;nbsp; For example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;If registered and Compliance with MDM/SCCM and Posture NOT_EQUALS=Compliance redirect for install the client and remediation portal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If registered and Compliance with MDM/SCCM and Posture EQUALS=Compliace permit the access. Is this the correct configuration?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4133821#M562269</guid>
      <dc:creator>Maiquel Consalter</dc:creator>
      <dc:date>2020-08-11T13:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4134222#M562291</link>
      <description>&lt;P&gt;ISE gets the MDM/DDM and ISE Posture information from two different sources. The MDM/DDM check is a real-time check against that system when the session hits that AuthZ rule. The ISE Posture check happens with the same logic (unless you the Posture lease enabled).&lt;/P&gt;
&lt;P&gt;That said, I don't believe the combination of both MDM/DDM and ISE Posture has been tested, so I don't know if you will run into any order-of-operations or race condition issues with the MDM/DDM check and URL redirection.&lt;/P&gt;
&lt;P&gt;IMHO, the MDM/DDM Compliance would likely provide similar if not more granular and centrally managed functionality than the ISE Posture Compliance checks, so I'm not sure what the value in using both would be.&lt;/P&gt;
&lt;P&gt;If you decide to use both, I would highly suggest extensive testing in a non-Production followed by a Production Pilot environment prior to rolling it out to the wider Prod environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 00:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4134222#M562291</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-08-12T00:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCCM DDM endpoint registration check for user session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4267981#M564604</link>
      <description>&lt;P&gt;Tks Greg.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 19:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sccm-ddm-endpoint-registration-check-for-user-session/m-p/4267981#M564604</guid>
      <dc:creator>Maiquel Consalter</dc:creator>
      <dc:date>2021-01-06T19:00:29Z</dc:date>
    </item>
  </channel>
</rss>

