<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent Endpoint Group Changes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513937#M537777</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&amp;nbsp; I'll let our customer know.&amp;nbsp; Looks like that bug needs to be updated to reference those fixes, as well as that the issue isn't just for Blacklisted devices but for any statically defined group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Sep 2016 13:40:16 GMT</pubDate>
    <dc:creator>JASON BOYERS</dc:creator>
    <dc:date>2016-09-05T13:40:16Z</dc:date>
    <item>
      <title>Prevent Endpoint Group Changes</title>
      <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513933#M537749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any way of preventing users from changing an endpoint that has already been manually entered into one endpoint group to another group?&amp;nbsp; And, is there a way of preventing users from putting in a MAC address in My Devices that has already been put into another group (whether a BYOD endpoint group or in another manually entered group.)&amp;nbsp; One of my customers has experienced these scenarios in two ways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Put a number of devices into an endpoint group as internal devices.&amp;nbsp; User logs into the device and goes through the BYOD process and now the endpoint is moved to the BYOD endpoint group.&amp;nbsp; I know that we can change the authorization policy order, including putting in a deny policy for the endpoint group if others log into it.&amp;nbsp; However, I don't think that the BYOD process should change the endpoint group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) A user put the MAC address for an internal endpoint into their My Devices portal, now associating that MAC with their account.&amp;nbsp; So, now that device can't access internal resources.&amp;nbsp; This could be entered by mistake or purposefully.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2016 13:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513933#M537749</guid>
      <dc:creator>JASON BOYERS</dc:creator>
      <dc:date>2016-08-30T13:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Endpoint Group Changes</title>
      <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513934#M537750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Onesies or twosies can be addressed by going to &lt;STRONG&gt;Context Visibility &amp;gt; Endpoints&lt;/STRONG&gt; and opening the endpoint details.&amp;nbsp; Click the &lt;STRONG&gt;Edit Endpoint&lt;/STRONG&gt; icon...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="99783" alt="endpoints1.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/99783_endpoints1.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;...and then choose &lt;STRONG&gt;Static Group Assignment&lt;/STRONG&gt; and&lt;STRONG&gt; Save&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="99784" alt="endpoints2.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/99784_endpoints2.PNG" style="height: 456px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For bulk entries, you can use the Import CSV function.&amp;nbsp; Again, start at &lt;STRONG&gt;Context Visibility &amp;gt; Endpoints&lt;/STRONG&gt; and select &lt;STRONG&gt;Import &amp;gt; Import From File&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="99785" alt="endpoints3.PNG" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/99785_endpoints3.PNG" style="height: 348px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can download a template for this file from the pop up dialog:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="99786" alt="endpoints4.PNG" class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/99786_endpoints4.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're looking for column AT in the template file.&amp;nbsp; Set that to &lt;STRONG&gt;TRUE&lt;/STRONG&gt; for all endpoints that you want to keep in a specific Endpoint Identity Group.&amp;nbsp; The Endpoint Identity Group is assigned in Column C.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="99787" alt="endpoints5.PNG" class="jive-image image-5" src="https://community.cisco.com/legacyfs/online/fusion/99787_endpoints5.PNG" style="height: 101px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once this template is filled and complete, upload it and the Endpoint Identity Groups will remain static for the endpoints assigned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These instruction are for ISE v2.1.&amp;nbsp; In 2.0 and below, go to &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Identities&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2016 14:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513934#M537750</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-08-30T14:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Endpoint Group Changes</title>
      <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513935#M537753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In all cases, when I look at the individual endpoints, whether internal endpoints uploaded via CSV or put in via the BYOD registration process, they all show as Static Group Assignment.&amp;nbsp; We need something that says that if it has a static group assignment, don't allow it to be changed (except by an administrator or such.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2016 14:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513935#M537753</guid>
      <dc:creator>JASON BOYERS</dc:creator>
      <dc:date>2016-08-30T14:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Endpoint Group Changes</title>
      <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513936#M537767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CSCuy83379 MyDevices portal overrides statically Blacklisted endpoint&lt;/P&gt;&lt;P&gt;is addressed in ISE 2.1, ISE 2.0.1 Patch 1, and ISE 1.4 Patch 8 and planned for next ISE 2.0 Patch release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With its fix, we may statically assign endpoints to Blacklist or a child group under Blacklist to avoid it being overridden by MyDevices. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 02:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513936#M537767</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-09-05T02:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Endpoint Group Changes</title>
      <link>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513937#M537777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&amp;nbsp; I'll let our customer know.&amp;nbsp; Looks like that bug needs to be updated to reference those fixes, as well as that the issue isn't just for Blacklisted devices but for any statically defined group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 13:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prevent-endpoint-group-changes/m-p/3513937#M537777</guid>
      <dc:creator>JASON BOYERS</dc:creator>
      <dc:date>2016-09-05T13:40:16Z</dc:date>
    </item>
  </channel>
</rss>

