<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IdentityAccessRestricted attribute in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959698#M585202</link>
    <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;In the "&lt;STRONG&gt;Active Directory Integration with Cisco ISE 2.x&lt;/STRONG&gt;" article, we read:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;IdentityAccessRestricted&lt;/STRONG&gt; attribute is set in order to support legacy policies and is not required in Cisco ISE because authentication fails if such conditions (for example, user disabled) are met.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain what does "&lt;SPAN&gt;to support legacy policies&lt;/SPAN&gt;" mean?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 06:40:54 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2023-11-15T06:40:54Z</dc:date>
    <item>
      <title>IdentityAccessRestricted attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959698#M585202</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;In the "&lt;STRONG&gt;Active Directory Integration with Cisco ISE 2.x&lt;/STRONG&gt;" article, we read:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;IdentityAccessRestricted&lt;/STRONG&gt; attribute is set in order to support legacy policies and is not required in Cisco ISE because authentication fails if such conditions (for example, user disabled) are met.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain what does "&lt;SPAN&gt;to support legacy policies&lt;/SPAN&gt;" mean?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 06:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959698#M585202</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-11-15T06:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: IdentityAccessRestricted attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959780#M585210</link>
      <description>&lt;P&gt;You need to provide document reference where you reading this, the context is depends on use case.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;to support legacy policies&lt;/SPAN&gt;&lt;SPAN&gt;" mean?&amp;nbsp; - i take this as backward compatibility.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 09:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959780#M585210</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-11-15T09:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: IdentityAccessRestricted attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959787#M585211</link>
      <description>&lt;P&gt;The link to the document is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Backward compatibility with what?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 10:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4959787#M585211</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-11-15T10:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: IdentityAccessRestricted attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4960438#M585243</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;- this dictionary still exists if there is an active AD Join configured, and it looks like this Boolean was previously available in older versions of ISE (or even from ACS) during the Authentication phase, to check if an account was disabled etc. - but ISE has changed since then, and you can't test this Boolean during Authentication. It's available during Authorization only. But not sure if that makes much sense, because you won't get that far if the Authentication fails. Perhaps you can force the If AuthFail CONTINUE and then test for this in AuthZ.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW, I can't find any mention of the text "&lt;STRONG&gt;IdentityAccessRestricted&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;attribute is set in order to support legacy policies and is not required in Cisco ISE because authentication fails if such conditions (for example, user disabled) are met." in the link you sent.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 06:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4960438#M585243</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-11-16T06:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: IdentityAccessRestricted attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4960611#M585246</link>
      <description>&lt;P&gt;Thanks for your reply...&lt;/P&gt;&lt;P&gt;The actual document is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I searched and found that Cisco has removed the following statement beginning from ISE 2.2 documents:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Additionally, you can can set the IdentityAccessRestricted attribute if conditions mentioned above (for example, user disabled) are met. IdentityAccessRestricted attribute is set in order to support legacy policies and is not required in Cisco ISE because authentication fails if such conditions (for example, user disabled) are met.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 11:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identityaccessrestricted-attribute/m-p/4960611#M585246</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-11-16T11:09:30Z</dc:date>
    </item>
  </channel>
</rss>

