<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Windows User Switch Account in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526870#M518024</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I was incorrect about NAM being a solution for this.&amp;nbsp; NAM EAP chaining is used when usually switching media state (example wired to wireless and wanting to present the machine and user auth in the user space). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a google search of teap eap chaining will give you some good articles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that microsoft doesn't switch user on dot1x when using fast user switching. Its tied to the original login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way around it would to either log the user off or do user auth only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think about security in this. Do you want to login to a machine with someone else stuff running in the background? What about accountability in this state?&amp;nbsp; userX has something bad running but I am logged in as UserY. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2018 15:46:52 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-02-07T15:46:52Z</dc:date>
    <item>
      <title>Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526865#M518013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guy's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are doing a machine and user authentication using a native client. which is working but there is a small issue that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we are doing log off and log in it works properly. But when the user does switch account the ise doesn't authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do this way? that we can a switch acocunt and have user and machine both authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have put a condition in the user checking was machine authenticated but it doesn't work with switch account in windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 14:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526865#M518013</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2018-02-07T14:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526866#M518015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The window supplicant is not able to send Machine authentication in the user-space. This is a known weakness in its capabilities&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should look into eap chaining with AnyConnect NAM If requiring to tie machine and user auth together&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also request that The customer request that Microsoft adopt the TEAP standards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526866#M518015</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-02-07T15:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526867#M518017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also note there is information out there already posted about trusted machine and trusted user scenarios&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526867#M518017</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-02-07T15:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526868#M518020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a current deployment using native deployment and the customer is not interested in using the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So intially he was ok with the solution but now he is requesting this feature of switch user option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it work's if we are doing only user authentication but when we are doing computer or user authentication, it keep's failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there no way to do this? as the machine is already authenticated but the its a new user who is logging on the machine can't it use its MAR's do the same??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526868#M518020</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2018-02-07T15:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526869#M518022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have links or something who have done a this kind of scenario?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526869#M518022</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2018-02-07T15:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526870#M518024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I was incorrect about NAM being a solution for this.&amp;nbsp; NAM EAP chaining is used when usually switching media state (example wired to wireless and wanting to present the machine and user auth in the user space). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a google search of teap eap chaining will give you some good articles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that microsoft doesn't switch user on dot1x when using fast user switching. Its tied to the original login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way around it would to either log the user off or do user auth only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think about security in this. Do you want to login to a machine with someone else stuff running in the background? What about accountability in this state?&amp;nbsp; userX has something bad running but I am logged in as UserY. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526870#M518024</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-02-07T15:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Windows User Switch Account</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526871#M518027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be necessary to have user logout of Windows and log back in with another account.&amp;nbsp; As Jason explained, there is no explicit AD logoff event or EAP logoff with Fast User Switching (FUS).&amp;nbsp; I recommend reaching out to Cisco account and requesting they submit enhancement to Tal Surasky (Cisco PM) on behalf of your company (or your customer) to support FUS.&amp;nbsp; There are technical ways where this scenario may be addressed, but would require code enhancements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 15:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-windows-user-switch-account/m-p/3526871#M518027</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-02-08T15:31:52Z</dc:date>
    </item>
  </channel>
</rss>

