<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE not pulling system domain information for MAC OSX devices during posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708444#M507596</link>
    <description>&lt;P&gt;Thanks for the input, Hosuk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this means Anyconnect will not automatically grab this information as the customer thinks it should, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What about Windows? does Anyconnect populate this domain information for Windows workstations automatically? If not, how is that information collected in the posture report.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Malavika&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 23:31:56 GMT</pubDate>
    <dc:creator>mparthan</dc:creator>
    <dc:date>2018-09-17T23:31:56Z</dc:date>
    <item>
      <title>ISE not pulling system domain information for MAC OSX devices during posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708295#M507591</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would the posture module populate system domain information for OSX by default even if the condition is not set as a requirement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see the system domain information populated in the posture report for Windows , however it is blank when a posture report is sent for the mac device. Refraining from uploading screenshots since it contains user data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For my Windows workstation, I have a condition defined to see if the workstation is domain joined or not,but dont have a similar condition for OSX.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is the system domain information populated? Does the Anyconnect gather it as a base attribute or based on the conditions enforced?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for helping with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--Malavika&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 19:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708295#M507591</guid>
      <dc:creator>mparthan</dc:creator>
      <dc:date>2018-09-17T19:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling system domain information for MAC OSX devices during posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708413#M507594</link>
      <description>&lt;P&gt;You can gather macOS AD domain membership using the plist files. Simple way is to find out if there is plist file (EXAMPLE as the AD domain name):&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;/Library/Preferences/OpenDirectory/DynamicData/Active\ Directory/EXAMPLE.plist&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;If you want to get more detailed information about the domain then you can also look into the plist file and compare the values within. Sample command here will allow you to view the content of plist file so you can craft matching ISE posture conditions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;sudo defaults read /Library/Preferences/OpenDirectory/DynamicData/Active\ Directory/EXAMPLE.plist&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Note that&amp;nbsp;it is not going to provide what is the data that is being matched, rather it will simply tell you whether your string matches with it or not. If you need to match multiple domains, you can create multiple conditions and combine them as compound conditions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 00:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708413#M507594</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-09-19T00:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling system domain information for MAC OSX devices during posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708444#M507596</link>
      <description>&lt;P&gt;Thanks for the input, Hosuk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this means Anyconnect will not automatically grab this information as the customer thinks it should, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What about Windows? does Anyconnect populate this domain information for Windows workstations automatically? If not, how is that information collected in the posture report.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Malavika&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 23:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708444#M507596</guid>
      <dc:creator>mparthan</dc:creator>
      <dc:date>2018-09-17T23:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling system domain information for MAC OSX devices during posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708445#M507597</link>
      <description>&lt;P&gt;If customer wants to see what the value is, then no. However, if customer wants to&amp;nbsp;validate whether the value is X then it is possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, AC Posture module does this automatically for Windows. If you want to similar result for AD joined macOS, please work with the PM team.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 23:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-system-domain-information-for-mac-osx-devices/m-p/3708445#M507597</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-09-17T23:51:01Z</dc:date>
    </item>
  </channel>
</rss>

