<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE-Admin access: Extra condition with external Username &amp;quot;contains/starts&amp;quot; with &amp;quot;x&amp;quot; ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564742#M517625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Michael, I misinterpreted your question!  I think the only way to accomplish what you want to do with ISE is to have those users with the “A” accounts be a member of a user group in the directory….so they could be a member of the “A” group to gain access to ISE administration.  I was reading your request as device administration for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Feb 2018 19:45:11 GMT</pubDate>
    <dc:creator>gbekmezi-DD</dc:creator>
    <dc:date>2018-02-26T19:45:11Z</dc:date>
    <item>
      <title>ISE-Admin access: Extra condition with external Username "contains/starts" with "x" ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564739#M517622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear experts, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while migrating some ACS solution,&amp;nbsp; our partner is challenged with an option, that exists in ACS 5.x, but seems to be hard to build in ISE.&lt;/P&gt;&lt;P&gt;The goal is to trigger and authorize with an&amp;nbsp; "external AD membership", which is fine, but then also "Require the Username" to fulfill an extra condition = (example)&amp;nbsp; "Begins with A".&lt;/P&gt;&lt;P&gt;So any ISE-Admin, who could authenticate and achieve a "Super-Power-Role", not only is member of a specific AD-Group, but also has been assigned a "Username = Starts with A". Only if both match, he would achieve the "Super-Power-Role".&lt;/P&gt;&lt;P&gt;Reason beeing, that structured User-Naming was enforced with this condition, whereas membership for other users in the same AD group could not be prevented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had a look at various UI elements, but did not achieve to find a way to squeeze this "Condition check" into the Authorization rules. &lt;/P&gt;&lt;P&gt;All we are offered is "External Group, whereas ACS has this setting as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2018-02-26_ACS-Settings.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115505_2018-02-26_ACS-Settings.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;/michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 17:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564739#M517622</guid>
      <dc:creator>mvassigh</dc:creator>
      <dc:date>2018-02-26T17:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-Admin access: Extra condition with external Username "contains/starts" with "x" ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564740#M517623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would this work for you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tested with Network Access:UserName STARTS_WITH as well as TACACS:User STARTS_WITH and they both work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 18:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564740#M517623</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-02-26T18:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-Admin access: Extra condition with external Username "contains/starts" with "x" ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564741#M517624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear George, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for highlighting the option, but would this apply for ISE-UI login process as well ?&lt;/P&gt;&lt;P&gt;I thought Network-Access is for "Pass-Through" not "Pass-To" Authentications, meaning that "some device" is asking for Authentication-Services, versus ISE-UI itself is asking for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does that make sense ?&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;/michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 19:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564741#M517624</guid>
      <dc:creator>mvassigh</dc:creator>
      <dc:date>2018-02-26T19:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-Admin access: Extra condition with external Username "contains/starts" with "x" ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564742#M517625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Michael, I misinterpreted your question!  I think the only way to accomplish what you want to do with ISE is to have those users with the “A” accounts be a member of a user group in the directory….so they could be a member of the “A” group to gain access to ISE administration.  I was reading your request as device administration for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 19:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-extra-condition-with-external-username-quot/m-p/3564742#M517625</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-02-26T19:45:11Z</dc:date>
    </item>
  </channel>
</rss>

