<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture authorization depending on Posture Check in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5164481#M591344</link>
    <description>&lt;P&gt;i'll check but pretty sure the requirements are mandator, audit, or disabled.&amp;nbsp; Also on the remediation's, i believe most of these run in user space so if something requires admin permissions not sure that will work.&amp;nbsp; I do plan on mocking up the remediation's.&lt;BR /&gt;&lt;BR /&gt;today our current NAC solution lets us put an endpoint into a remediation network with a limited network view when some set of checks pass and some set of checks fail.&amp;nbsp; We were hoping to do that with ISE.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2024 13:30:44 GMT</pubDate>
    <dc:creator>ryanbess</dc:creator>
    <dc:date>2024-08-22T13:30:44Z</dc:date>
    <item>
      <title>ISE Posture authorization depending on Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5163973#M591332</link>
      <description>&lt;P&gt;We have a want to give an endpoint some level of access even though a single posture policy fails.&amp;nbsp; As an example lets say we're checking for&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Some Registry key value&lt;/P&gt;&lt;P&gt;2. Some X mgmt. tool installed&lt;/P&gt;&lt;P&gt;3. Some AM tool installed&lt;/P&gt;&lt;P&gt;With the three checks, lets say the mgmt. tool isn't installed but the AM and Registry key is there, is it possible to give a different authorization for that machine?&amp;nbsp; The example would be we could present the user a message box saying go into software center (in the windows use case) and install X tool.&amp;nbsp; The diffrent authorization policy would give line of site to the server that software center needs to download the tool and install it.&amp;nbsp; &amp;nbsp;As best we can tell posture is either a Pass or a Fail.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 17:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5163973#M591332</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-08-21T17:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture authorization depending on Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5164109#M591338</link>
      <description>&lt;P&gt;Have you checked out Work Centers - Posture - Policy Elements - Requirements?&amp;nbsp; Along with that you would use the Remediations section just above it (I'm referencing ISE 3.1).&amp;nbsp; Seems like this could be the direction you need.&amp;nbsp; There will be more to it, but hopefully this will help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 22:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5164109#M591338</guid>
      <dc:creator>WILLIAM BAUER</dc:creator>
      <dc:date>2024-08-21T22:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture authorization depending on Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5164481#M591344</link>
      <description>&lt;P&gt;i'll check but pretty sure the requirements are mandator, audit, or disabled.&amp;nbsp; Also on the remediation's, i believe most of these run in user space so if something requires admin permissions not sure that will work.&amp;nbsp; I do plan on mocking up the remediation's.&lt;BR /&gt;&lt;BR /&gt;today our current NAC solution lets us put an endpoint into a remediation network with a limited network view when some set of checks pass and some set of checks fail.&amp;nbsp; We were hoping to do that with ISE.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 13:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-authorization-depending-on-posture-check/m-p/5164481#M591344</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-08-22T13:30:44Z</dc:date>
    </item>
  </channel>
</rss>

