<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - Authenticate local windows account in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5130582#M590090</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;we are using dot1x close mode authenticating AD machines and users, and we want to be able to authenticte local win account too. (beside user AD domain account).&lt;/P&gt;
&lt;P&gt;We think to add the local PC admin user account as ISE local user and use that in the authz policy too.&lt;/P&gt;
&lt;P&gt;Would this work? Do you see any problem with that?&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 11:51:34 GMT</pubDate>
    <dc:creator>babalao</dc:creator>
    <dc:date>2024-06-14T11:51:34Z</dc:date>
    <item>
      <title>ISE - Authenticate local windows account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5130582#M590090</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;we are using dot1x close mode authenticating AD machines and users, and we want to be able to authenticte local win account too. (beside user AD domain account).&lt;/P&gt;
&lt;P&gt;We think to add the local PC admin user account as ISE local user and use that in the authz policy too.&lt;/P&gt;
&lt;P&gt;Would this work? Do you see any problem with that?&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 11:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5130582#M590090</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-06-14T11:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Authenticate local windows account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132275#M590116</link>
      <description>&lt;P&gt;You can't do this because ISE has no access to check the endpoints' local user account passwords.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also not sure that the Windows 802.1X supplicant will perform a user network authentication when that PC is not domain joined. I might be wrong - you should test that. But either way, even if it did, then you will have to add all the local user accounts and their passwords into ISE as Network Access accounts. How do get those passwords without asking each user? Maybe you could come up with some Frankenstein solution to integrate this into ISE via a portal or something - but it cannot guarantee that the user account information in ISE will always represent the local accounts on user machines.&amp;nbsp; That's why we have AD &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2024 22:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132275#M590116</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-16T22:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Authenticate local windows account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132790#M590140</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;it would be only for the admin local user,and is the same on all PCs.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 19:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132790#M590140</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-06-17T19:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Authenticate local windows account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132807#M590142</link>
      <description>&lt;P&gt;I don't know if Windows perform network authentication on local accounts. Something to test in the lab with a Windows PC - I don't have one available at the moment. The Windows Supplicant must be configured for User and Computer Auth.&lt;/P&gt;
&lt;P&gt;As far as the ISE Policy Set is concerned, in the Authentication part, you must have an Identity Source Sequence that includes the AD Join Point, and Internal Users. The order is not important, but you should consider which one should be searched first for performance and security reasons perhaps.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 20:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authenticate-local-windows-account/m-p/5132807#M590142</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-17T20:28:21Z</dc:date>
    </item>
  </channel>
</rss>

