<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Intune querying behavior. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5129185#M590022</link>
    <description>&lt;P&gt;Hi Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Awesome, thanks for confirming my suspicion.&amp;nbsp;&lt;BR /&gt;I've added the MDMServerName as an example from an environment in which there is a Production MDM and an Acceptance MDM.&lt;/P&gt;
&lt;P&gt;Flagged as solution!&lt;/P&gt;
&lt;P&gt;Many thanks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2024 17:31:57 GMT</pubDate>
    <dc:creator>Michaelkarper</dc:creator>
    <dc:date>2024-06-12T17:31:57Z</dc:date>
    <item>
      <title>ISE Intune querying behavior.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5128443#M589971</link>
      <description>&lt;P&gt;Hey all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a discussion about the ISE Intune querying behavior when hitting an authorization policy where there is no MDM condition/attribute defined. I do believe it does not do the query as it's not configured in the indentity source sequence as a join point.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I correct in the examples provided below? :&lt;/P&gt;
&lt;P&gt;Policy conditions:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Top Policy:&amp;nbsp;&lt;BR /&gt;Wireless_802.1X&lt;BR /&gt;Radius·Called-Station-ID -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CONTAINS _ MDM_SSID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AND&lt;BR /&gt;MDM·MDMServerName -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;EQUALS _ Intune_Dummy_server&amp;nbsp; AND&lt;BR /&gt;MDM·DeviceCompliantStatus&amp;nbsp; -&amp;nbsp; EQUALS _ Compliant&lt;/P&gt;
&lt;P&gt;In this case Intune_Dummy_server is queried.&lt;/P&gt;
&lt;P&gt;Below top policy:&amp;nbsp;&lt;BR /&gt;Wireless_802.1X&lt;BR /&gt;Radius·Called-Station-ID -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CONTAINS _&amp;nbsp; AD_SSID&amp;nbsp; &amp;nbsp;AND&lt;BR /&gt;Network Access·EapAuthentication - EQUALS _ EAP-TLS&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AND&lt;BR /&gt;Dummy-AD·ExternalGroups -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EQUALS _ Dummy.domain/Users/Domain Users&lt;BR /&gt;&lt;BR /&gt;In this case Intune_Dummy_server is NOT queried.&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 10:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5128443#M589971</guid>
      <dc:creator>Michaelkarper</dc:creator>
      <dc:date>2024-06-11T10:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Intune querying behavior.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5128723#M590005</link>
      <description>&lt;P&gt;An Identity Source Sequence is queried during the Authentication process, which is separate from the External MDM lookup that happens during the Authorization process.&lt;/P&gt;
&lt;P&gt;ISE will perform an MDM lookup during the Authorization process if any of the MDM dictionary attributes are defined as a matching condition in the Authorization Policy that is evaluated.&lt;BR /&gt;If you only have a single External MDM defined, it is not required to use the '&lt;SPAN&gt;MDMServerName' attribute. That is mainly needed when you have multiple MDMs in use to inform ISE which MDM it should perform the lookup on.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5128723#M590005</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-06-11T22:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Intune querying behavior.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5129185#M590022</link>
      <description>&lt;P&gt;Hi Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Awesome, thanks for confirming my suspicion.&amp;nbsp;&lt;BR /&gt;I've added the MDMServerName as an example from an environment in which there is a Production MDM and an Acceptance MDM.&lt;/P&gt;
&lt;P&gt;Flagged as solution!&lt;/P&gt;
&lt;P&gt;Many thanks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 17:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-intune-querying-behavior/m-p/5129185#M590022</guid>
      <dc:creator>Michaelkarper</dc:creator>
      <dc:date>2024-06-12T17:31:57Z</dc:date>
    </item>
  </channel>
</rss>

