<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows 11 ISE posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5344156#M598793</link>
    <description>&lt;P&gt;I configured posture policy which use (windows 10(all)) as operating system criteria. and all posture conditions using windows 10 also. but windows 11 PCs still be scanned for posture.&lt;/P&gt;
&lt;P&gt;Note : posture requirements still in audit state.&lt;/P&gt;
&lt;P&gt;Can someone explain that behavior.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Nov 2025 19:06:03 GMT</pubDate>
    <dc:creator>AAA184</dc:creator>
    <dc:date>2025-11-03T19:06:03Z</dc:date>
    <item>
      <title>Windows 11 ISE posture</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5344156#M598793</link>
      <description>&lt;P&gt;I configured posture policy which use (windows 10(all)) as operating system criteria. and all posture conditions using windows 10 also. but windows 11 PCs still be scanned for posture.&lt;/P&gt;
&lt;P&gt;Note : posture requirements still in audit state.&lt;/P&gt;
&lt;P&gt;Can someone explain that behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 19:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5344156#M598793</guid>
      <dc:creator>AAA184</dc:creator>
      <dc:date>2025-11-03T19:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 11 ISE posture</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5344312#M598798</link>
      <description>&lt;P&gt;Apologies if I misunderstood your question. You configured posture assessment for Win 10 and it's not working with Win 11, is this what are you asking about? if so, that won't work because it won't match Win 11 machines. You would need to add Win 11 in the conditions similar to what you've done for Win 10.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 09:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5344312#M598798</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-11-04T09:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 11 ISE posture</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5356024#M599326</link>
      <description>&lt;P&gt;What he is saying is that windows 11 is being detected by the ISE posture as windows 10 and even though he only has windows 10 posture rules, windows 11 machines are being postured.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have the same issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Waynieack_0-1766006497104.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/256817iDE3679C096015122/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Waynieack_0-1766006497104.png" alt="Waynieack_0-1766006497104.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 21:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5356024#M599326</guid>
      <dc:creator>Waynieack</dc:creator>
      <dc:date>2025-12-17T21:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 11 ISE posture</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5356356#M599336</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;By design, something which is obviously creating more problems than ones which were presumably to be fixed, Windows 11 shows itself as Windows 10 with a different build version than Windows 10:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/555857/windows-11-product-name-in-registry?page=2" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/555857/windows-11-product-name-in-registry?page=2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Use Registry check to differentiate and match between Windows 10 and Windows 11; from path "&lt;SPAN&gt;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion", match on "DisplayVersion" to be 21H2 values or "CurrentBuildNumber" to be higher than 20000.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here's an example of using Registry Keys as matching conditions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/cisco-ise-posture-and-os-selections/td-p/4110666" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/cisco-ise-posture-and-os-selections/td-p/4110666&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cristian.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 00:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5356356#M599336</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2025-12-19T00:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 11 ISE posture</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5362290#M599569</link>
      <description>&lt;P&gt;I have registry conditions like that for other stuff but it doesn't help with the Cisco managed pr_W11_64_Hotfixes conditions. Regardless of what I put the the rules, that operating system check in the pr_W11_64_Hotfixes compound condition is going to keep the windows 11 machines that show up as windows 10 from hitting the hotfix check.&amp;nbsp; We don't allow windows 10 machines, so all the rules that point to pr_W11_64_Hotfixes are set for (windows 10 or windows 11), but that OS check on the&amp;nbsp;pr_W11_64_Hotfixes that I can't change is the issue. I know I can copy it, but then I would be manually managing the rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Waynieack_2-1768606027110.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/257946iACE119775563770D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Waynieack_2-1768606027110.png" alt="Waynieack_2-1768606027110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 23:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-11-ise-posture/m-p/5362290#M599569</guid>
      <dc:creator>Waynieack</dc:creator>
      <dc:date>2026-01-16T23:27:17Z</dc:date>
    </item>
  </channel>
</rss>

