<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Endpoint API Create with Authoization Policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302180#M565902</link>
    <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Hello!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I am trying to automate the importing of devices into ISE. The current workflow is make a csv with 3 fields from the Context Visibility =&amp;gt; Endpoints =&amp;gt; Import from file.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The 3 fields are&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;MAC Address | Endpoint_Policy | Identity_Group&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I can use the following payload, but cannot find a parameter to set the Authorization Policy. Is this something that is in the API?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; "ERSEndPoint"&lt;/SPAN&gt;&lt;SPAN&gt; : {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "mac"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;"01:01:01:01:01:01"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "groupId"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;"111111-111111-1111-1111-11111111"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "staticGroupAssignment"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; }&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We are on ISE 2.4 at the moment.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 05 Mar 2021 17:26:26 GMT</pubDate>
    <dc:creator>BrandonSharp37516</dc:creator>
    <dc:date>2021-03-05T17:26:26Z</dc:date>
    <item>
      <title>Cisco ISE Endpoint API Create with Authoization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302180#M565902</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Hello!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I am trying to automate the importing of devices into ISE. The current workflow is make a csv with 3 fields from the Context Visibility =&amp;gt; Endpoints =&amp;gt; Import from file.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The 3 fields are&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;MAC Address | Endpoint_Policy | Identity_Group&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I can use the following payload, but cannot find a parameter to set the Authorization Policy. Is this something that is in the API?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; "ERSEndPoint"&lt;/SPAN&gt;&lt;SPAN&gt; : {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "mac"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;"01:01:01:01:01:01"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "groupId"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;"111111-111111-1111-1111-11111111"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "staticGroupAssignment"&lt;/SPAN&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; }&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We are on ISE 2.4 at the moment.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Mar 2021 17:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302180#M565902</guid>
      <dc:creator>BrandonSharp37516</dc:creator>
      <dc:date>2021-03-05T17:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Endpoint API Create with Authoization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302238#M565906</link>
      <description>&lt;P&gt;AFAIK that is not supported.&amp;nbsp; I would suggest taking a peek at the SDK via: &amp;nbsp;https://&amp;lt;pan ip&amp;gt;:9060/ers/sdk#&lt;/P&gt;
&lt;P&gt;There you can find examples and supported payload syntax/content.&amp;nbsp; This is pulled directly from the SDK (ISE 2.7p3) for the creation of endpoints:&lt;/P&gt;
&lt;PRE id="content_Create" class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt;JSON
&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;{&lt;/SPAN&gt;
  &lt;SPAN class="str"&gt;"ERSEndPoint"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="pun"&gt;{&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"name"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"name"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"description"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"description"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"mac"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"00:01:02:03:04:05"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"profileId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"profileId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"staticProfileAssignment"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="kwd"&gt;false&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"groupId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"groupId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"staticGroupAssignment"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="kwd"&gt;true&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"portalUser"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"portalUser"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"identityStore"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"identityStore"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"identityStoreId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"identityStoreId"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
    &lt;SPAN class="str"&gt;"customAttributes"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="pun"&gt;{&lt;/SPAN&gt;
      &lt;SPAN class="str"&gt;"customAttributes"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="pun"&gt;{&lt;/SPAN&gt;
        &lt;SPAN class="str"&gt;"key1"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"value1"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;
        &lt;SPAN class="str"&gt;"key2"&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"value2"&lt;/SPAN&gt;
      &lt;SPAN class="pun"&gt;}&lt;/SPAN&gt;
    &lt;SPAN class="pun"&gt;}&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 20:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302238#M565906</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-05T20:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Endpoint API Create with Authoization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302291#M565908</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, that looks similar to the API Create call for ise/ers/config/endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;{
  "ERSEndPoint" : {
    "id" : "id",
    "name" : "name",
    "description" : "description",
    "mac" : "00:01:02:03:04:05",
    "profileId" : "profileId",
    "staticProfileAssignment" : false,
    "groupId" : "groupId",
    "staticGroupAssignment" : true,
    "portalUser" : "portalUser",
    "identityStore" : "identityStore",
    "identityStoreId" : "identityStoreId",
    "customAttributes" : {
      "customAttributes" : {
        "key1" : "value1",
        "key2" : "value2"
      }
    },
    "mdmAttributes" : {
      "mdmServerName" : "MdmServerName",
      "mdmReachable" : true,
      "mdmEnrolled" : false,
      "mdmComplianceStatus" : false,
      "mdmOS" : "iOS",
      "mdmManufacturer" : "Apple Inc.",
      "mdmModel" : "iPad",
      "mdmSerial" : "10000000001",
      "mdmEncrypted" : false,
      "mdmPinlock" : false,
      "mdmJailBroken" : false,
      "mdmIMEI" : "IMEI",
      "mdmPhoneNumber" : "Phone Number"
    }
  }
}&lt;/PRE&gt;&lt;P&gt;Still doesn't look like a way to apply an Authorization Policy programmatically.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 21:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4302291#M565908</guid>
      <dc:creator>BrandonSharp37516</dc:creator>
      <dc:date>2021-03-05T21:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Endpoint API Create with Authoization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4306936#M566117</link>
      <description>&lt;P&gt;Brandon,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We cover this specific topic using 2 different methods : 1) static endpoint group and 2) custom attributes.&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;See &lt;STRONG&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623" target="_self"&gt;ISE ERS API Examples&lt;/A&gt;&lt;/STRONG&gt; :&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: disc; margin-left: 15px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-155297388" target="_blank" rel="nofollow noopener noreferrer"&gt;Create an Endpoint Group and Assign an Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--1523074356" target="_blank" rel="nofollow noopener noreferrer"&gt;Create Endpoint Group&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-964438477" target="_blank" rel="nofollow noopener noreferrer"&gt;Create Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 15px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--972098705" target="_blank" rel="nofollow noopener noreferrer"&gt;Create an Endpoint with Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-1644496847" target="_blank" rel="nofollow noopener noreferrer"&gt;Define ISE Endpoint Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--162957616" target="_blank" rel="nofollow noopener noreferrer"&gt;Create an Endpoint with Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Your Authorization Policy is totally separate from the endpoint profile and looks like this:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;IdentityGroup-Name EQUALS Endpoint Identity Groups:&lt;STRONG&gt;MyGroupName&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;See&lt;A class="" href="https://community.cisco.com/t5/security-documents/ise-authentication-and-authorization-policy-reference/ta-p/3850472#toc-hId--2106958069" target="_blank" rel="nofollow noopener noreferrer"&gt;&amp;nbsp;Static Endpoint Group(s)&lt;/A&gt; for the details.&lt;/P&gt;
&lt;P&gt;Also, tune into our &lt;A href="https://cs.co/ise-webinars" target="_self"&gt;&lt;STRONG&gt;ISE Webinar&lt;/STRONG&gt; &lt;/A&gt;in April when I will discuss and demo ISE REST APIs !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 14 Mar 2021 02:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-endpoint-api-create-with-authoization-policy/m-p/4306936#M566117</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-14T02:59:38Z</dc:date>
    </item>
  </channel>
</rss>

