<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Impact of Moving AD Group on ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702481#M577725</link>
    <description>&lt;P&gt;If the AD groups paths change, then yes you would need to go the policy sets and updating the rules.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2022 11:14:22 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2022-10-13T11:14:22Z</dc:date>
    <item>
      <title>Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701409#M577692</link>
      <description>&lt;P&gt;Currently I'm using ISE in front of most network devices and referencing an AD group for admins.&amp;nbsp; That group membership isn't changing, but I do need to move it to another OU within Active Directory.&amp;nbsp; What changes do I need to make in ISE, if any, since the path to the group will be changing?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 16:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701409#M577692</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2022-10-11T16:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701418#M577693</link>
      <description>&lt;P&gt;First i would add other OU to ISE and test it, before removing old one.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 16:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701418#M577693</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-11T16:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701432#M577694</link>
      <description>&lt;P&gt;Can I add a 2nd group with the same name?&amp;nbsp; Path is currently:&lt;/P&gt;
&lt;P&gt;mydomain.local/DomainGroup/Groups/NetAdmins&lt;/P&gt;
&lt;P&gt;And would be moving to the following path:&lt;/P&gt;
&lt;P&gt;mydomain.local/IT/SecurityGroups/NetAdmins&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 17:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701432#M577694</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2022-10-11T17:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701857#M577700</link>
      <description>&lt;P&gt;You can add another one to same rule, if the user belong to mydomain.local/DomainGroup/Groups/NetAdmins or mydomain.local/IT/SecurityGroups/NetAdmins&lt;/P&gt;
&lt;P&gt;Add one test user in the new mydomain.local/IT/SecurityGroups/NetAdmins and test it.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 11:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701857#M577700</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-12T11:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701864#M577701</link>
      <description>&lt;P&gt;If you are using the AD groups on the policy rules then you wouldn't need to do anything on ISE as the AD group path wouldn't change if you change the OU. However, if you are using the OUs, or, if you want to start using the OUs then you need to set up your policies to look at the OUs. Take a look please at this post of mine that shows all the required steps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bluenetsec.com/how-to-use-active-directory-ous-in-cisco-ise-authorization-rules/" target="_blank"&gt;https://bluenetsec.com/how-to-use-active-directory-ous-in-cisco-ise-authorization-rules/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 11:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701864#M577701</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-12T11:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701982#M577703</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; I'm currently doing authorization based on AD group membership, not the OU an account resides in.&lt;/P&gt;
&lt;P&gt;If I go into ISE and the following path:&lt;/P&gt;
&lt;P&gt;Administration --&amp;gt; External Identity Sources --&amp;gt; Active Directory --&amp;gt; Groups (after selecting my domain)&lt;/P&gt;
&lt;P&gt;I see the groups I'm referring to listed, along w/ the path to the group. If I go to:&lt;/P&gt;
&lt;P&gt;Work Centers --&amp;gt; Policy Elements&lt;/P&gt;
&lt;P&gt;and then select the element I'm using it shows the following:&lt;/P&gt;
&lt;P&gt;mydomain:ExternalGroups&lt;BR /&gt;Equals --&amp;gt; current path to group in AD.&lt;/P&gt;
&lt;P&gt;I tested moving the group in AD last night to the new OU and confirmed I was still able to login to devices, but the path never go updated. Does ISE just go based on the SID of the group once the group is added to ISE? I was able to click "Add" under groups and locate the new path, but as the SID is the same as the old it wouldn't allow me to save it. And when I manually edited the currently defined group with the new path it failed to save as the group is in use in a policy.&lt;/P&gt;
&lt;P&gt;It seems to work fine, just wanted it to be consistent in case someone else has to look at it in the future.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4701982#M577703</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2022-10-12T14:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702091#M577704</link>
      <description>&lt;P&gt;You can select the groups, remove them, and then re-add them.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 17:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702091#M577704</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-12T17:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702123#M577705</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; I just have to go back in and update my element then to reflect the new group (same name, new path)?&amp;nbsp; Will any rules error out as the element will be invalid while I'm making the changes?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 17:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702123#M577705</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2022-10-12T17:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of Moving AD Group on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702481#M577725</link>
      <description>&lt;P&gt;If the AD groups paths change, then yes you would need to go the policy sets and updating the rules.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 11:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/impact-of-moving-ad-group-on-ise/m-p/4702481#M577725</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-13T11:14:22Z</dc:date>
    </item>
  </channel>
</rss>

