<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sponsor Portal with authentication active directory in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704250#M507762</link>
    <description>You have to add your AD groups into ISE on the Administration-&amp;gt;Identity Management-&amp;gt;External Identity Sources-&amp;gt;Active Directory.  Then go to the Groups tab and map in the desired AD groups and then assign the AD groups to the sponsor groups.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 10 Sep 2018 17:59:34 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-09-10T17:59:34Z</dc:date>
    <item>
      <title>Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3703272#M507746</link>
      <description>&lt;PRE class="tw-data-text tw-ta tw-text-small" dir="ltr" data-placeholder="Tradución" data-fulltext=""&gt;&lt;SPAN&gt;I have an ISE 1.4 standalone in the ise I have an active directory configured. I did an authentication test to the active directory and the authentication was successful.

I am also setting up a portal sponsor and the administrators of the portal sponsor will be users defined in a group of the active directory.

but when I use a user of the active directory in the portal sponsor it shows me "authentication error"

But in the sponsor group I specify that you use the active directory group.

What am I doing wrong or what is the configuration that I need?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-ta tw-text-small" dir="ltr" data-placeholder="Tradución" data-fulltext=""&gt;&lt;SPAN&gt;I have to define it also in Adminitration&amp;gt; Identity Management&amp;gt; Identity Source Sequences
???&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-ta tw-text-small" dir="ltr" data-placeholder="Tradución" data-fulltext=""&gt;&amp;nbsp;&lt;/PRE&gt;</description>
      <pubDate>Sat, 08 Sep 2018 04:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3703272#M507746</guid>
      <dc:creator>nstr1</dc:creator>
      <dc:date>2018-09-08T04:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3703368#M507751</link>
      <description>&lt;P&gt;All portals in ISE use identity source sequences (ISS) to tell them where to authenticate users against.&amp;nbsp; So even if you have one authentication source you need to define a sequence.&amp;nbsp; If you are just going to use active directory then device an ISS called Active_Directory and assign your AD definition to it.&amp;nbsp; Then assign Active_Directory as the ISS to your sponsor portal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I usually build an ISS called AD_Local and assign Active Directory and Internal Users so I can setup local accounts to test various conditions as needed.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 14:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3703368#M507751</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-08T14:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704231#M507753</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I did what you say assign the ISS with the AD and in my Sponsor it also defines the ISS, but it still does not authenticate me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; partly I must define, "Sponsor Group" because in the sponsor gruop defines which group of the AD authenticated in the sponor ?????&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704231#M507753</guid>
      <dc:creator>nstr1</dc:creator>
      <dc:date>2018-09-10T17:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704232#M507754</link>
      <description />
      <pubDate>Mon, 10 Sep 2018 17:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704232#M507754</guid>
      <dc:creator>nstr1</dc:creator>
      <dc:date>2018-09-10T17:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704234#M507756</link>
      <description>&lt;P&gt;You have to assign an AD group to the sponsor groups to get into the Sponsor Portal.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704234#M507756</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T17:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704248#M507758</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am using the sponsor group default, there specify the group of the AD, but in my configuration in which part I add this group ??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704248#M507758</guid>
      <dc:creator>nstr1</dc:creator>
      <dc:date>2018-09-10T17:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704250#M507762</link>
      <description>You have to add your AD groups into ISE on the Administration-&amp;gt;Identity Management-&amp;gt;External Identity Sources-&amp;gt;Active Directory.  Then go to the Groups tab and map in the desired AD groups and then assign the AD groups to the sponsor groups.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704250#M507762</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T17:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704257#M507764</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ok, also configure it&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 18:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704257#M507764</guid>
      <dc:creator>nstr1</dc:creator>
      <dc:date>2018-09-10T18:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor Portal with authentication active directory</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704354#M507766</link>
      <description>&lt;P&gt;Please look at the logs and see what is going on from the steps in the logs.&lt;/P&gt;
&lt;P&gt;Also make sure that the authentication policy has MAB first and your MAB authentication results in URL-redirection etc.&lt;/P&gt;
&lt;P&gt;Your authorization policy should have the right authorization profile as well to allow guest acess.&lt;/P&gt;
&lt;P&gt;Finally make sure you change the sponsor portal and add AD under the right group.&lt;/P&gt;
&lt;P&gt;Check out the flow in Guest deployment guide. Though this is for latest, some of the workflows are the same.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-deployment-guide/ta-p/3640475?attachment-id=160597" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-deployment-guide/ta-p/3640475?attachment-id=160597&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Krishnan&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 20:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-portal-with-authentication-active-directory/m-p/3704354#M507766</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2018-09-10T20:05:32Z</dc:date>
    </item>
  </channel>
</rss>

