<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 : Sponsor groupe  with AD user can see all guest accounts. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-sponsor-groupe-with-ad-user-can-see-all-guest-accounts/m-p/4461368#M569583</link>
    <description>&lt;P&gt;Do you have a match policy for ALL_ACCOUNTS groups configured for 'Other conditions (optional)'? If not, then you shouldn't be matching the ALL_ACCOUNTS group and suggest creating a TAC SR for troubleshooting.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Sep 2021 21:22:16 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2021-09-07T21:22:16Z</dc:date>
    <item>
      <title>ISE 2.7 : Sponsor groupe  with AD user can see all guest accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-sponsor-groupe-with-ad-user-can-see-all-guest-accounts/m-p/4461175#M569577</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I created a new sponsor groupe with user member from AD.&lt;BR /&gt;and with the right to manage "only account sponsor has created"&lt;/P&gt;&lt;P&gt;The pb is they can see and manage all guest account.&lt;/P&gt;&lt;P&gt;I noticed that I have this pb only with AD user , not Internal users.&lt;BR /&gt;I noticed also, that if I remove all member from AD in the list, they still can login...!&lt;BR /&gt;However, they are not specify in any other sponsor group.&lt;/P&gt;&lt;P&gt;It is like the AD-User are automatically members of group "ALL_ACCOUNTS", even if thy are not configured in it.&lt;BR /&gt;I user ISE v2.7 patch2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Michel Misonne&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 15:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-sponsor-groupe-with-ad-user-can-see-all-guest-accounts/m-p/4461175#M569577</guid>
      <dc:creator>mmisonne</dc:creator>
      <dc:date>2021-09-07T15:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 : Sponsor groupe  with AD user can see all guest accounts.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-sponsor-groupe-with-ad-user-can-see-all-guest-accounts/m-p/4461368#M569583</link>
      <description>&lt;P&gt;Do you have a match policy for ALL_ACCOUNTS groups configured for 'Other conditions (optional)'? If not, then you shouldn't be matching the ALL_ACCOUNTS group and suggest creating a TAC SR for troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 21:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-sponsor-groupe-with-ad-user-can-see-all-guest-accounts/m-p/4461368#M569583</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2021-09-07T21:22:16Z</dc:date>
    </item>
  </channel>
</rss>

