<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE not pulling all identity attributes from AD. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607287#M530504</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to use the device group condition to create an authorization policy based on user attributes from the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It didn't work out and also got this from the report.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="geo_code 24100.JPG" class="image-1 jive-image" src="/legacyfs/online/fusion/105722_geo_code 24100.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Code 24100 seems to be the problem. Cause I have deployed similar policy for another client and code 24100 seems to be the only strange report I can see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Mar 2017 08:43:53 GMT</pubDate>
    <dc:creator>jahamilton1</dc:creator>
    <dc:date>2017-03-28T08:43:53Z</dc:date>
    <item>
      <title>ISE not pulling all identity attributes from AD.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607287#M530504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to use the device group condition to create an authorization policy based on user attributes from the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It didn't work out and also got this from the report.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="geo_code 24100.JPG" class="image-1 jive-image" src="/legacyfs/online/fusion/105722_geo_code 24100.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Code 24100 seems to be the problem. Cause I have deployed similar policy for another client and code 24100 seems to be the only strange report I can see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 08:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607287#M530504</guid>
      <dc:creator>jahamilton1</dc:creator>
      <dc:date>2017-03-28T08:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling all identity attributes from AD.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607288#M530505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you see these attributes on the client if you use the AD test tool on external identity sources?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 14:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607288#M530505</guid>
      <dc:creator>Oliver Laue</dc:creator>
      <dc:date>2017-03-28T14:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling all identity attributes from AD.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607289#M530506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I do. All required required attributes were pulled when I did a test&lt;/P&gt;&lt;P&gt;tool.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 18:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607289#M530506</guid>
      <dc:creator>jahamilton1</dc:creator>
      <dc:date>2017-03-28T18:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not pulling all identity attributes from AD.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607290#M530507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error implies the attribute is empty. If your AD test is done with the same user, are you seeing it differently?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I configured an authz profile to return the attribute "mail" from AD. It does NOT give 24100 when the AD user has non-empty value for this attribute; whereas it gives 24100 for an user not configured for this attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-03-30 at 8.32.25 PM.png" class="image-1 jive-image" height="135" src="/legacyfs/online/fusion/105875_Screen Shot 2017-03-30 at 8.32.25 PM.png" style="height: 134.90672451193058px; width: 299px;" width="299" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-03-30 at 8.41.11 PM.png" class="jive-image image-2" src="/legacyfs/online/fusion/105878_Screen Shot 2017-03-30 at 8.41.11 PM.png" style="height: 118px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Mar 2017 03:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-pulling-all-identity-attributes-from-ad/m-p/3607290#M530507</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-03-31T03:42:46Z</dc:date>
    </item>
  </channel>
</rss>

