<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple MDM Server Scopes (Microsoft Intune) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4041198#M558621</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Once you've done the MDM integration, make use of the MDM Dictionary Attributes in your authorization policies. See the attached guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 19:36:10 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2020-03-05T19:36:10Z</dc:date>
    <item>
      <title>Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036108#M558369</link>
      <description>&lt;P&gt;We have a scenario where we have multiple external MDM servers that need to be queried depending on the source device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do we create an authorization policy that defines a particular device to a particular MDM server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e. Device A querying MDM A and Device B querying MDM B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried to create the policy below however we have been unsuccessful so far:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Policy 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;MDM·MDMServerName Equals "MDM A"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MDM·DeviceCompliantStatus Equals Compliant&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Policy 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;MDM·MDMServerName Equals "MDM B"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MDM·DeviceCompliantStatus Equals Compliant&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What appears to be happening is that ISE will only query one of the MDM servers meaning that it will only allow access to either Device A or Device depending on which MDM server was queried first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ISE version 2.6 Patch Update 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 13:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036108#M558369</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-02-26T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036155#M558372</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Whilst this may be possible , I feel it contradicts the purpose of integrated MDM. Meaning , probably working towards an 'inclusive' MDM_solution &lt;FONT color="#008000"&gt;is &lt;STRONG&gt;better&lt;/STRONG&gt;&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 14:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036155#M558372</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-02-26T14:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036177#M558373</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately we need to stick with Microsoft Intune as the MDM provider but have the ability within ISE to service two separate companies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any ideas on how i can define which MDM server to query on my authorization rules as the current setup only queries one and not the other?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 14:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036177#M558373</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-02-26T14:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036185#M558374</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Below are some threads I found on the subject&amp;nbsp; , but then again, even with ISE in between '&lt;FONT color="#FF0000"&gt;multiple&amp;nbsp; MDM'&lt;/FONT&gt; in my view contradicts with &lt;FONT color="#008000"&gt;&lt;STRONG&gt;solid MDM&lt;/STRONG&gt;&lt;/FONT&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/multiple-mdm-solutions-and-a-single-ise-cluster/m-p/3060070" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/multiple-mdm-solutions-and-a-single-ise-cluster/m-p/3060070&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/multi-mdm-support/td-p/3493890" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/multi-mdm-support/td-p/3493890&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/multiple-mdm-support-similar-to-identity-store-sequence/td-p/3562197" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/multiple-mdm-support-similar-to-identity-store-sequence/td-p/3562197&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 14:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036185#M558374</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-02-26T14:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036450#M558397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;This is easily achievable; you just need to find a differentiator between the devices which will be checked against MDM1 and devices which will be checked against MDM2, and use that differentiator as a condition in your authorization policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 20:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036450#M558397</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-02-26T20:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036507#M558405</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295226"&gt;@Cristian Matei&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am fairly new to ISE so unsure as to how I can differentiate based on host names in the authorisation rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All devices in MDM1 hostname starts with GP and all devices in MDM2 start with TR, how would the rules be updated to reflect this? could you give me an example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you achieved this before using two different MDM servers?&amp;nbsp;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 22:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4036507#M558405</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-02-26T22:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple MDM Server Scopes (Microsoft Intune)</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4041198#M558621</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Once you've done the MDM integration, make use of the MDM Dictionary Attributes in your authorization policies. See the attached guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 19:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-mdm-server-scopes-microsoft-intune/m-p/4041198#M558621</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-05T19:36:10Z</dc:date>
    </item>
  </channel>
</rss>

