<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD Windows Non-Admin User in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688085#M508300</link>
    <description>&lt;P&gt;Non-admin user won't be able to complete the BYOD flow as it requires&amp;nbsp;running executable&amp;nbsp;and also access to the certificate store.&amp;nbsp;In the fas-user-switching, yes what you describe is correct, since the first user did not log off, from the network perspective, the first user is still logged in.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 14:03:03 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2018-08-14T14:03:03Z</dc:date>
    <item>
      <title>BYOD Windows Non-Admin User</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688064#M508299</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just as a sanity check, consider the scenario where we have multiple users (both admin and non-admin) in Windows running on the same machine. If a non-admin user runs the browser as an admin and follows the BYOD flow, is it possible for the non-admin user to install the BYOD cert?&lt;/P&gt;
&lt;P&gt;Also, if an admin user (after having completed the BYOD flow) authenticates against ISE using the cert, and then using fast user switching a non-admin user logs in (without sending any EAPOL logoff message). Will the non-admin user be able to reuse the existing authenticated session from the admin user?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Oriol&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 13:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688064#M508299</guid>
      <dc:creator>omadrile</dc:creator>
      <dc:date>2018-08-14T13:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Windows Non-Admin User</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688085#M508300</link>
      <description>&lt;P&gt;Non-admin user won't be able to complete the BYOD flow as it requires&amp;nbsp;running executable&amp;nbsp;and also access to the certificate store.&amp;nbsp;In the fas-user-switching, yes what you describe is correct, since the first user did not log off, from the network perspective, the first user is still logged in.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688085#M508300</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-14T14:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Windows Non-Admin User</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688120#M508301</link>
      <description>It’s not recommended to use BYOD with shared machines &lt;BR /&gt;&lt;BR /&gt;The whole point of the feature is really to onboard devices used by a single person. Register a device to a person. Otherwise you have the same Mac flipping between different ownership as a portal user id. This maybe even introduces issues as haven’t tried &lt;BR /&gt;&lt;BR /&gt;Would recommend looking into deploying one  (perhaps a machine cert) for identifying the machine and then rely upon user credentials such as CWA chaining as an example &lt;BR /&gt;&lt;BR /&gt;Or using a certificate management platform such as sccm or gpo push out user certainty and manage that way&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-windows-non-admin-user/m-p/3688120#M508301</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-08-14T14:33:19Z</dc:date>
    </item>
  </channel>
</rss>

