<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User or Computer Authentication option... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5234078#M593649</link>
    <description>&lt;P&gt;The following article explains how this works with traditional EAP methods.&lt;BR /&gt;&lt;A href="https://www.networkworld.com/article/940452/machine-authentication-and-user-authentication.html" target="_blank"&gt;https://www.networkworld.com/article/940452/machine-authentication-and-user-authentication.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I also describe and illustrate how this works with both traditional EAP methods and TEAP in my blog here.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-296059835" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-296059835&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2024 01:43:28 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2024-12-09T01:43:28Z</dc:date>
    <item>
      <title>User or Computer Authentication option...</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233846#M593643</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;As you know, there is several authentication scenarios in Windows native supplicant. One of them is "User or Authentication" option:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1733644808835.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235427iB88E159EFB3D51A2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rezaalikhani_0-1733644808835.png" alt="rezaalikhani_0-1733644808835.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Based on the official documents, by selecting "&lt;STRONG&gt;User or Computer Authentication&lt;/STRONG&gt;" option, Windows performs an 802.1X authentication with computer credentials before displaying the Windows logon screen. Windows performs another 802.1X authentication with user credentials after the user has logged on.&lt;/P&gt;&lt;P&gt;Based on the above statement, Microsoft should choose &lt;STRONG&gt;AND&lt;/STRONG&gt; instead of &lt;STRONG&gt;OR&lt;/STRONG&gt; for this option. Right?&lt;/P&gt;&lt;P&gt;Is there any scenario you know which forces the &lt;STRONG&gt;OR&lt;/STRONG&gt; operation (the computer authentication or user authentication)?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 08:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233846#M593643</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-12-08T08:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: User or Computer Authentication option...</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233851#M593644</link>
      <description>&lt;P&gt;If I recall correctly, the addition of user authentication is tied to EAP chaining in which it is a logical AND.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Edit: Re-reading my initial response didn’t answer your question at all. This appears to be a limitation of the OS rather than ISE which can be configured to accept in an AND/OR manner.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 08:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233851#M593644</guid>
      <dc:creator>stephan.l.martin1</dc:creator>
      <dc:date>2024-12-08T08:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: User or Computer Authentication option...</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233866#M593645</link>
      <description>&lt;P&gt;Short answer is No with native supplicant, but you have machine access restriction feature on ISE which basically caches your machine auth for the defined period of time, between this time only user authentication happens since previous machine auth is already cached, unless windows device goers thought a reboot or complete logout.&lt;BR /&gt;There are some restriction, pros and cons that you can read &lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 10:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5233866#M593645</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2024-12-08T10:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: User or Computer Authentication option...</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5234078#M593649</link>
      <description>&lt;P&gt;The following article explains how this works with traditional EAP methods.&lt;BR /&gt;&lt;A href="https://www.networkworld.com/article/940452/machine-authentication-and-user-authentication.html" target="_blank"&gt;https://www.networkworld.com/article/940452/machine-authentication-and-user-authentication.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I also describe and illustrate how this works with both traditional EAP methods and TEAP in my blog here.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-296059835" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-296059835&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 01:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5234078#M593649</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-12-09T01:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: User or Computer Authentication option...</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5234139#M593652</link>
      <description>&lt;P&gt;Exactly useful for me. Thank you...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 06:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-computer-authentication-option/m-p/5234139#M593652</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-12-09T06:05:51Z</dc:date>
    </item>
  </channel>
</rss>

