<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: windows 10 trying to do machine auth thru ise in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4196376#M564266</link>
    <description>&lt;P&gt;do ise have a mechanism to reject an authentication request (for a period of time) after a laptop keeps failing to authenticate?&amp;nbsp;&lt;/P&gt;&lt;P&gt;then once the duration is finished ise will allow laptop for a new auth request.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2020 03:09:55 GMT</pubDate>
    <dc:creator>Meuserid1979</dc:creator>
    <dc:date>2020-12-10T03:09:55Z</dc:date>
    <item>
      <title>windows 10 trying to do machine auth thru ise</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195682#M564235</link>
      <description>&lt;P&gt;Hi experts, im not really sure how to title this discussion. the scenario is this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;wireless network is on 802.1x authentication thru ise (version 2.7).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;windows10 &amp;lt;---&amp;gt;cisco AP&amp;lt;---&amp;gt;WLC &amp;lt;--&amp;gt; Cisco ise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AD is integrated to ise. users are authenticating thru a lists of AD OUs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authC - AD usernames/password are being checked against those selected OUs populated on ise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authZ - is either permit access or dynamic vlan assignement&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on windows 10 wireless properties , "user or computer authentication" is the selected option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;machine authentication is disabled on ISE. But on ise logs, some windows are trying to do machine authentication first then after a while the user authentication will be done and user will get connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is that windows10 machine behaviour or there is some settings on ise that can be changed so that the laptops will stop doing the machine authentication? thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 07:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195682#M564235</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2020-12-09T07:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 trying to do machine auth thru ise</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195703#M564236</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;when you boot the machine it will try to login using machine authentication&lt;BR /&gt;(before the user login). The same thing when you logoff from your machine,&lt;BR /&gt;it will try machine authentication to stay connected as there is no user&lt;BR /&gt;details in the credentials store (lsass.exe).&lt;BR /&gt;&lt;BR /&gt;This is normal pattern with windows clients whether using native supplicant&lt;BR /&gt;or anyconnect supplicant. If you disable machine authm you will start&lt;BR /&gt;getting issues like machine not connected to network at boot with password&lt;BR /&gt;changed. The user will attempt new password but it will accept cached&lt;BR /&gt;password only as it can't see AD.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Dec 2020 08:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195703#M564236</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-12-09T08:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 trying to do machine auth thru ise</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195748#M564239</link>
      <description>&lt;P&gt;thanks . appreciate the reply.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 10:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4195748#M564239</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2020-12-09T10:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: windows 10 trying to do machine auth thru ise</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4196376#M564266</link>
      <description>&lt;P&gt;do ise have a mechanism to reject an authentication request (for a period of time) after a laptop keeps failing to authenticate?&amp;nbsp;&lt;/P&gt;&lt;P&gt;then once the duration is finished ise will allow laptop for a new auth request.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-trying-to-do-machine-auth-thru-ise/m-p/4196376#M564266</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2020-12-10T03:09:55Z</dc:date>
    </item>
  </channel>
</rss>

