<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 not fetching AD-Groups-Name attribute from Active Director in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831435#M581608</link>
    <description>&lt;P&gt;From a AD permissions perspective, group matching issues can be caused by the ISE machine account not having the permission to read tokenGroups. See the following document for the required AD permissions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_F19556CAD5C949B58DF89334E2C6255D" target="_blank" rel="noopener"&gt;Active Directory Integration with Cisco ISE 2.x&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are also bug fixes related to AD Group matching in various patches for ISE 2.7 and you did not specify what patch level you have installed. If you are not using the latest patch for 2.7 (currently patch 9), then you should start by updating to the latest patch.&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 00:46:10 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2023-05-09T00:46:10Z</dc:date>
    <item>
      <title>ISE 2.7 not fetching AD-Groups-Name attribute from Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831419#M581605</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;
&lt;P&gt;I´m doing an eap chaining lab using ISE 2.7 and Windows Server 2016. Almost everything is working fine but I´m stuck in this "problem". I want to create Authz rules based on AD Security Groups but during a user authentication, ISE for some reason don´t retrieve the AD Groups in which the user belongs to, So the Authz fail and the authentication is denied.&lt;/P&gt;
&lt;P&gt;Have you guys ever seen this behavior? What can it be?&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 23:23:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831419#M581605</guid>
      <dc:creator>Isildur</dc:creator>
      <dc:date>2023-05-08T23:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 not fetching AD-Groups-Name attribute from Active Director</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831433#M581607</link>
      <description>&lt;P&gt;Perform a test user authentication from ISE GUI. Under External identity Stores &amp;gt; Select Active Directory Join point name &amp;gt; Click Test user and check if you are able to fetch user attribute normally or not. If not, it may be a permission issue on AD.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 00:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831433#M581607</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2023-05-09T00:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 not fetching AD-Groups-Name attribute from Active Director</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831435#M581608</link>
      <description>&lt;P&gt;From a AD permissions perspective, group matching issues can be caused by the ISE machine account not having the permission to read tokenGroups. See the following document for the required AD permissions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_F19556CAD5C949B58DF89334E2C6255D" target="_blank" rel="noopener"&gt;Active Directory Integration with Cisco ISE 2.x&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are also bug fixes related to AD Group matching in various patches for ISE 2.7 and you did not specify what patch level you have installed. If you are not using the latest patch for 2.7 (currently patch 9), then you should start by updating to the latest patch.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 00:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4831435#M581608</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-05-09T00:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 not fetching AD-Groups-Name attribute from Active Director</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4833723#M581699</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1435125"&gt;@Isildur&lt;/a&gt;&amp;nbsp;- perhaps you're running &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc47015" target="_self"&gt;into this defect&amp;nbsp;&lt;SPAN&gt;CSCvz85074&lt;/SPAN&gt;&lt;/A&gt; that also affects ISE 2.7&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 20:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4833723#M581699</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-11T20:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 not fetching AD-Groups-Name attribute from Active Director</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4834558#M581726</link>
      <description>&lt;P&gt;I was using ISE 2.7 with no patch and the problem was resolved after I updated to the last patch.&lt;/P&gt;
&lt;P&gt;Thank you very much guys!!&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 20:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-not-fetching-ad-groups-name-attribute-from-active/m-p/4834558#M581726</guid>
      <dc:creator>Isildur</dc:creator>
      <dc:date>2023-05-12T20:26:33Z</dc:date>
    </item>
  </channel>
</rss>

