<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Authorize only Domain Computers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280991#M595943</link>
    <description>&lt;P&gt;A screenshot of the Authorization Policy is not enough information. You would need to share detailed information from the Live Logs as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;has suggested multiple times for us to provide any meaningful assistance.&lt;/P&gt;
&lt;P&gt;You could be running into an issue with Authentication due to &lt;A href="https://community.cisco.com/t5/network-access-control/windows-11-22h2-credential-guard-enforcement/td-p/4695655" target="_blank" rel="noopener"&gt;Credential Guard&lt;/A&gt; being enabled by MS.&lt;/P&gt;
&lt;P&gt;You could be running into group-matching issues if the ISE computer accounts do not have read permission to the 'tokenGroups' attribute.&lt;/P&gt;
&lt;P&gt;You can also try using the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#task_8E095069A94148B487E673B07376E014" target="_blank" rel="noopener"&gt;Test User&lt;/A&gt; tool to do a lookup against AD for the computer account and associated groups by using 'host/&amp;lt;computer name&amp;gt;' as the username.&lt;/P&gt;
&lt;P&gt;There could be any number of reasons the session is not hitting your authorization policy.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 00:12:20 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2025-04-14T00:12:20Z</dc:date>
    <item>
      <title>ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280491#M595923</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In ISE we'd like to have a Polcy Set that Authorizes only domain computers.&lt;BR /&gt;Now we're using ExternalGroups EQUALS domain/Users/Domain Computers but this does not seem to work.&lt;BR /&gt;Other ways like PrimaryGroupID EQALS 515 also do not seem to do the trick for us.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 08:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280491#M595923</guid>
      <dc:creator>quadrabe</dc:creator>
      <dc:date>2025-04-11T08:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280494#M595924</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/897370"&gt;@quadrabe&lt;/a&gt; is the supplicant configured to perform machine/computer authentication? &lt;BR /&gt;Are you using PEAP/MSCHAPv2 or EAP-TLS? &lt;BR /&gt;If EAP-TLS are you using a Certificate Authentication Profile and performing a lookup into AD? - &lt;A href="https://integrate.uk.com/ise-certificate-authentication/" target="_self"&gt;example&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What do the ISE Live logs indicate for the authentication? Please provide screenshots.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 08:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280494#M595924</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-04-11T08:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280509#M595926</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; said the supplicant must be configured for Machine auth only, or User or Machine, with the latest one connecting while in the Windows login screen with the machine name, and then with the user credentials after log in.&lt;/P&gt;
&lt;P&gt;Additionally, during the authentication phase, you can limit the access to RADIUS Usernames like ".*your.domain.net", but I have seen a problem with few Win11 where they are not sending the full FQDN but only the hostname, so failing to be authenticated unless a backup policy to accept any AD credential would be below.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 08:55:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280509#M595926</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2025-04-11T08:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280512#M595927</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes the supplicant is configured to use machine authentication, we use&amp;nbsp;&lt;SPAN&gt;PEAP/MSCHAPv2.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 09:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280512#M595927</guid>
      <dc:creator>quadrabe</dc:creator>
      <dc:date>2025-04-11T09:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280519#M595929</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/897370"&gt;@quadrabe&lt;/a&gt; as requested, please provide screenshots of your live logs, this would provide information on how we can determine the problem.&lt;/P&gt;
&lt;P&gt;Also provide screenshots of your authorisation rules.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 10:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280519#M595929</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-04-11T10:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280539#M595930</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Here is a screenshot.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 10:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280539#M595930</guid>
      <dc:creator>quadrabe</dc:creator>
      <dc:date>2025-04-11T10:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authorize only Domain Computers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280991#M595943</link>
      <description>&lt;P&gt;A screenshot of the Authorization Policy is not enough information. You would need to share detailed information from the Live Logs as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;has suggested multiple times for us to provide any meaningful assistance.&lt;/P&gt;
&lt;P&gt;You could be running into an issue with Authentication due to &lt;A href="https://community.cisco.com/t5/network-access-control/windows-11-22h2-credential-guard-enforcement/td-p/4695655" target="_blank" rel="noopener"&gt;Credential Guard&lt;/A&gt; being enabled by MS.&lt;/P&gt;
&lt;P&gt;You could be running into group-matching issues if the ISE computer accounts do not have read permission to the 'tokenGroups' attribute.&lt;/P&gt;
&lt;P&gt;You can also try using the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#task_8E095069A94148B487E673B07376E014" target="_blank" rel="noopener"&gt;Test User&lt;/A&gt; tool to do a lookup against AD for the computer account and associated groups by using 'host/&amp;lt;computer name&amp;gt;' as the username.&lt;/P&gt;
&lt;P&gt;There could be any number of reasons the session is not hitting your authorization policy.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 00:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorize-only-domain-computers/m-p/5280991#M595943</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-04-14T00:12:20Z</dc:date>
    </item>
  </channel>
</rss>

