<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If self-registration user coincide with an AD user name, login fai in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4516503#M571592</link>
    <description>&lt;P&gt;Thanks Thomas. It was a missconfiguration, in the Identity source sequence I placed internal users over the guest users, and we had these users internally defined (but with AD authentication) in the ISE Identity. Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Dec 2021 07:28:27 GMT</pubDate>
    <dc:creator>morabusa</dc:creator>
    <dc:date>2021-12-10T07:28:27Z</dc:date>
    <item>
      <title>If self-registration user coincide with an AD user name, login fail</title>
      <link>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4503403#M571067</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a Guest WLAN with CWA using a self-registering portal with sponsors, and if clients create a username which already exists on AD, the login fails because the ISE tries to authenticate the user with the AD, even when I have only specified "Internal Users" in the sequence. Is there a way to make work this scenario when the self-registered user name coincide with a current existing AD user?&lt;/P&gt;&lt;P&gt;EDIT: Adding more information, lets supose that there is a user called John Smith, then we have a username created in the AD called jsmith. Then the same user wants to register in the self-register portal specifying his first name and last name, and the ISE also tries to generate a new username called jsmith. Then when the user tries to log in to the Guest WLAN, it fails because AD domain is not included in the identity source sequence for Guest access (due to a internal company policy).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 10:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4503403#M571067</guid>
      <dc:creator>morabusa</dc:creator>
      <dc:date>2021-11-16T10:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: If self-registration user coincide with an AD user name, login fai</title>
      <link>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4516421#M571587</link>
      <description>&lt;P&gt;The ISE guest user database is internal to ISE and completely separate from AD.&lt;/P&gt;
&lt;P&gt;ISE cannot create users in AD.&lt;/P&gt;
&lt;P&gt;Please show us the actual ISE LiveLog Details from the failure so we can see the reason Why if fails according to ISE.&lt;/P&gt;
&lt;P&gt;It would potentially help to see what your Guest Authorization Rules are in your ISE Policy Set in case you messed with the default ones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 04:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4516421#M571587</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-10T04:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: If self-registration user coincide with an AD user name, login fai</title>
      <link>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4516503#M571592</link>
      <description>&lt;P&gt;Thanks Thomas. It was a missconfiguration, in the Identity source sequence I placed internal users over the guest users, and we had these users internally defined (but with AD authentication) in the ISE Identity. Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 07:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/if-self-registration-user-coincide-with-an-ad-user-name-login/m-p/4516503#M571592</guid>
      <dc:creator>morabusa</dc:creator>
      <dc:date>2021-12-10T07:28:27Z</dc:date>
    </item>
  </channel>
</rss>

