<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static group assignment and Identity group assignment changing by themselves in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4119914#M561741</link>
    <description>&lt;P&gt;Under a certain block of end points with ISE, we currently have&amp;nbsp;&lt;SPAN&gt;Static Group Assignment checked and a specific&amp;nbsp;Identity group assignment set for a large block of devices withing our ISE environment. High School Chromebooks that have not had much activity on the network recently. Randomly the&amp;nbsp;Static Group Assignment will become unchecked and the&amp;nbsp;Identity group assignment with change to "workstation".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We cannot find the cause of why the end points are changing themselves and looking for input from the community.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2020 13:22:46 GMT</pubDate>
    <dc:creator>KeelynHenning0941</dc:creator>
    <dc:date>2020-07-16T13:22:46Z</dc:date>
    <item>
      <title>Static group assignment and Identity group assignment changing by themselves</title>
      <link>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4119914#M561741</link>
      <description>&lt;P&gt;Under a certain block of end points with ISE, we currently have&amp;nbsp;&lt;SPAN&gt;Static Group Assignment checked and a specific&amp;nbsp;Identity group assignment set for a large block of devices withing our ISE environment. High School Chromebooks that have not had much activity on the network recently. Randomly the&amp;nbsp;Static Group Assignment will become unchecked and the&amp;nbsp;Identity group assignment with change to "workstation".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We cannot find the cause of why the end points are changing themselves and looking for input from the community.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 13:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4119914#M561741</guid>
      <dc:creator>KeelynHenning0941</dc:creator>
      <dc:date>2020-07-16T13:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Static group assignment and Identity group assignment changing by themselves</title>
      <link>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4120131#M561749</link>
      <description>The most common reason this happens is that the endpoints are being purged by an endpoint purge rule. By default they typically won't be, but if someone set up a rule based on inactivity days, then there is no filter for static identity group = true.  Check on those here, https://&amp;lt;ise admin ip&amp;gt;/admin/#administration/administration_identitymanagement/administration_identitymanagement_generalsettings/endpointPurge&lt;BR /&gt;&lt;BR /&gt;In the past, there was also a profiling bug with DHCP helpers being sent at the same time to two different PSNs. That would cause the endpoint to be reset and lose its static mapping, however that was fixed at least a year and a half ago or more though.</description>
      <pubDate>Thu, 16 Jul 2020 17:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4120131#M561749</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-07-16T17:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Static group assignment and Identity group assignment changing by themselves</title>
      <link>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4120670#M561764</link>
      <description>&lt;P&gt;Thank you for your reply!&lt;/P&gt;&lt;P&gt;I already looked at this before but took another look for good measure. There were two Purge rules created, one of which could have possibility contained these devices at one time but when we checked there were no EndPoints listed under the Identity Group associated with the condition. To elevate this being the issue, we deleted both the Purge rule and the Identity Group associated as they were not needed anyway.&lt;/P&gt;&lt;P&gt;We ran another test that I believe is part of the problem but I still need to continue troubleshoot to see if it is related. This issue has been occurring with Chromebooks for a school district. We took a random Chromebook, looked over it's EndPoint settings, it was currently configured with the correct Policy and Identity Group and we added it to the guest network. After the device was on the Guest network, the static assignment went away, the Policy assignment changed, the Static Group assignment was still checked, and the Identity Group Assignment had changed.&lt;/P&gt;&lt;P&gt;We checked the EndPoint Identity Group EndPoints for the group this was changed to and we could see the EndPoint Profile listed and they were all marked Static Group Assignment = false.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this issue lays somewhere in the Profiler Policy so that is where I am with troubleshooting now.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 14:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-group-assignment-and-identity-group-assignment-changing/m-p/4120670#M561764</guid>
      <dc:creator>KeelynHenning0941</dc:creator>
      <dc:date>2020-07-17T14:22:34Z</dc:date>
    </item>
  </channel>
</rss>

