<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Matches for users with two AD accounts. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4395517#M566990</link>
    <description>&lt;P&gt;Currently we are using Subject Alternate Name, I think I can change this the Common Name to resolve the issue, is there a best practices or which fits best for that particular deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 14:35:29 GMT</pubDate>
    <dc:creator>joeharb</dc:creator>
    <dc:date>2021-04-29T14:35:29Z</dc:date>
    <item>
      <title>Multiple Matches for users with two AD accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4395476#M566985</link>
      <description>&lt;P&gt;We have specific users that have both an Admin account and a normal account.&amp;nbsp; We are using EAP-TLS and have found that they fail authentication.&amp;nbsp; ISE responds with a:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24324&lt;/TD&gt;&lt;TD&gt;Identity resolution detected multiple matching accounts&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24417&lt;/TD&gt;&lt;TD&gt;User's Groups retrieval from Active Directory failed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The radius user name is from the &lt;A href="mailto:first.lastname@csiweb.com" target="_blank" rel="noopener"&gt;first.lastname@csiweb.com&lt;/A&gt;.&amp;nbsp; I am trying to determine what attributes are being retrieved that makes it think that the accounts are the same...the sAMAccount and UPN are different in AD.&lt;/P&gt;&lt;P&gt;Would the debug logs give me some of this information?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4395476#M566985</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2021-04-29T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Matches for users with two AD accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4395517#M566990</link>
      <description>&lt;P&gt;Currently we are using Subject Alternate Name, I think I can change this the Common Name to resolve the issue, is there a best practices or which fits best for that particular deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 14:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4395517#M566990</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2021-04-29T14:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Matches for users with two AD accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4396389#M567034</link>
      <description>&lt;P&gt;CSCvu35802&amp;nbsp;Shared email for AD users fail to retrieve groups,ISE shows multiple account found in forest&lt;/P&gt;
&lt;P&gt;might be what you are hitting.&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2021 05:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4396389#M567034</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-05-01T05:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Matches for users with two AD accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4397142#M567099</link>
      <description>&lt;P&gt;Thanks for the response, in looking at the Bug, I don't know if I can change to UPN as the UPN reflects our internal domain&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182356"&gt;@csi&lt;/a&gt;.corp, while the username is @csiweb.com (from the Subject Alt Name).&amp;nbsp; I am going to test with the Certificate profile change the Common Name as that seems to be unique.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 16:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-matches-for-users-with-two-ad-accounts/m-p/4397142#M567099</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2021-05-03T16:28:24Z</dc:date>
    </item>
  </channel>
</rss>

