<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Provisioning with Workflow in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470515#M518930</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer wants to distribute BYOD certificate from ISE to endpoints (mainly windows10) with sponsor's approval workflow.&lt;/P&gt;&lt;P&gt;I came up with two scenarios.&lt;/P&gt;&lt;P&gt;Could you please let me know they are supported or is there any recommendation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pattern1: Manual EndPoint Group Assign scenario&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;1. A new device connect to network &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;2. Network Setup Assistance &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;3. After NSP finished, device firstly added to "PreApproval" endpoint group&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;4. Than, managers manually assign the device from "PreApproval" to "Approved" endpoint group.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P&gt;Pattern2: Sponsored BYOD scenario&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;1. A new device connect to Guest network (guest network which is only used for NSP onboarding)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;2. Using Guest Approval flow, Managers approve the device.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;3. The device will redirected to DeviceRegistration and NSP process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Itaru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Dec 2017 05:58:49 GMT</pubDate>
    <dc:creator>iurikura</dc:creator>
    <dc:date>2017-12-25T05:58:49Z</dc:date>
    <item>
      <title>Certificate Provisioning with Workflow</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470515#M518930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer wants to distribute BYOD certificate from ISE to endpoints (mainly windows10) with sponsor's approval workflow.&lt;/P&gt;&lt;P&gt;I came up with two scenarios.&lt;/P&gt;&lt;P&gt;Could you please let me know they are supported or is there any recommendation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pattern1: Manual EndPoint Group Assign scenario&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;1. A new device connect to network &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;2. Network Setup Assistance &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;3. After NSP finished, device firstly added to "PreApproval" endpoint group&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;4. Than, managers manually assign the device from "PreApproval" to "Approved" endpoint group.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P&gt;Pattern2: Sponsored BYOD scenario&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;1. A new device connect to Guest network (guest network which is only used for NSP onboarding)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;2. Using Guest Approval flow, Managers approve the device.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;3. The device will redirected to DeviceRegistration and NSP process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Itaru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Dec 2017 05:58:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470515#M518930</guid>
      <dc:creator>iurikura</dc:creator>
      <dc:date>2017-12-25T05:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Provisioning with Workflow</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470516#M518932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You’re looking for a sponsored byod flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please start by navigating to our ISE Community dashboard&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Http://cs.co/ise-community&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to byod section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;look for sponsor byod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Dec 2017 15:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470516#M518932</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-25T15:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Provisioning with Workflow</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470517#M518935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the reply. &lt;/P&gt;&lt;P&gt;I read below. &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-73856"&gt;Cisco ISE Sponsored BYOD&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understood this scenario was assumed that a guest account for employee be made by sponsor. &lt;/P&gt;&lt;P&gt;Can we do the same thing with self-sponsored-guest scenario ? &lt;/P&gt;&lt;P&gt; Firstly, an employee create a guest account.&lt;/P&gt;&lt;P&gt; Secondly, a manager approve it. &lt;/P&gt;&lt;P&gt; Then, the employee can proceed to device registration and provisioning flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Itaru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Dec 2017 06:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470517#M518935</guid>
      <dc:creator>iurikura</dc:creator>
      <dc:date>2017-12-26T06:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Provisioning with Workflow</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470518#M518938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I believe should work but would need to test the flow in lab&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Dec 2017 12:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-provisioning-with-workflow/m-p/3470518#M518938</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-26T12:39:26Z</dc:date>
    </item>
  </channel>
</rss>

