<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Nested Groups Configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306479#M566090</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;You've been so helpful.&lt;/P&gt;&lt;P&gt;Final one, I've google it but not getting much info. Any idea on how to push the Compliance Module via SCCM..?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 19:00:51 GMT</pubDate>
    <dc:creator>Srinivasan Nagarajan</dc:creator>
    <dc:date>2021-03-12T19:00:51Z</dc:date>
    <item>
      <title>AD Nested Groups Configuration for CPP policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306390#M566083</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We've ISE 2.6 patch 8 and started upgrading the CM from 3.6 to 4.3 on a phased approach by adding a specific CPP policy at the top with the AD groups as other condition. If user is part of the AD group, they'll be provisioned with 4.3, all other users will continue via 3.6 access (fallback).&lt;/P&gt;&lt;P&gt;Now, we're planning to add the groups into the AD group which is used in the CPP configuration to accomplish the phased approach. Now, my query is on the Nested groups. Please assist.&lt;/P&gt;&lt;P&gt;Main Group: CM4.3_VPN_group&lt;BR /&gt;Nested group: Sales, Finance, IT, HR, Marketing&lt;/P&gt;&lt;P&gt;1.If ISE can query the nested AD groups?&lt;BR /&gt;2.And if yes, what’s the maximum hierarchy level that it can look into?&lt;BR /&gt;3. Should the Nested groups (Sales, Finance, IT, HR, Marketing) be added into the External Identity Sources -&amp;gt; AD Group Name -&amp;gt; Groups&lt;/P&gt;&lt;P&gt;Note: Currently, only the main group is added under the&amp;nbsp;External Identity Sources&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 19:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306390#M566083</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-03-12T19:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306414#M566084</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1.If ISE can query the nested AD groups?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Yes.&amp;nbsp; They will need to be added in ISE if you wish to target those groups as a condition in policies.&lt;BR /&gt;&lt;SPAN&gt;2.And if yes, what’s the maximum hierarchy level that it can look into?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Good question.&amp;nbsp; Honestly not sure if there is one.&lt;BR /&gt;&lt;SPAN&gt;3. Should the Nested groups (Sales, Finance, IT, HR, Marketing) be added into the External Identity Sources -&amp;gt; AD Group Name -&amp;gt; Groups&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Depends if you wish to target the exact group.&amp;nbsp; Otherwise all ISE needs is the top level group to reference.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 16:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306414#M566084</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-12T16:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306423#M566085</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks for the reply. From the above reply, I assume (nested groups not required to be added under &lt;SPAN&gt;External Identity Sources -&amp;gt; AD Group Name -&amp;gt; Groups)&amp;nbsp;&lt;/SPAN&gt;and adding only the Main Group would suffice the CPP/Authorization policy to achieve the phased approach to work.&lt;/P&gt;&lt;P&gt;Please confirm?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 17:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306423#M566085</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-03-12T17:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306437#M566086</link>
      <description>&lt;P&gt;&lt;SPAN&gt;From the above reply, I assume (nested groups not required to be added under&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;External Identity Sources -&amp;gt; AD Group Name -&amp;gt; Groups)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and adding only the Main Group would suffice the CPP/Authorization policy to achieve the phased approach to work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Yes. That is correct.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 17:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306437#M566086</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-12T17:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306479#M566090</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;You've been so helpful.&lt;/P&gt;&lt;P&gt;Final one, I've google it but not getting much info. Any idea on how to push the Compliance Module via SCCM..?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 19:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306479#M566090</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-03-12T19:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration for CPP policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306509#M566091</link>
      <description>&lt;P&gt;No problem happy to help.&amp;nbsp; Not really an SCCM guy so not much help there.&amp;nbsp; However, you do have the ability to rely on ISE CPP to upgrade the compliance module.&amp;nbsp; I assume you already are aware of that.&amp;nbsp; Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 19:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4306509#M566091</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-12T19:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: AD Nested Groups Configuration for CPP policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4307588#M566153</link>
      <description>&lt;P&gt;Hi again&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm if it’s resource intensive on ISE if we push the compliance module for all users in a single shot via CPP?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 15:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ad-nested-groups-configuration-for-cpp-policy/m-p/4307588#M566153</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-03-15T15:40:26Z</dc:date>
    </item>
  </channel>
</rss>

