<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP Chaining Both Authz Rule Not Matching in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5368872#M599762</link>
    <description>&lt;P&gt;Unfortunately this issue is related to&amp;nbsp;&lt;SPAN class="custom-text-color-light subheader-large"&gt;CSCws30603 (&amp;nbsp;&lt;SPAN class="subheader-large"&gt;ISE unable to fetch user group membership if user belongs to more than 20 groups ).&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="custom-text-color-light subheader-large"&gt;&lt;SPAN class="subheader-large"&gt;Is there time line can someone share when this bug will be resolved&amp;nbsp; ? for version 3.5.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="custom-text-color-light subheader-large"&gt;&lt;SPAN class="subheader-large"&gt;What are the workarounds if we cannot use Device/User GroupMembership due to this bug to use in AuthC and AuthC Profile ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="flex flex-left flex-wrap"&gt;
&lt;DIV class="base-margin-right"&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 09 Feb 2026 23:29:16 GMT</pubDate>
    <dc:creator>MSJ1</dc:creator>
    <dc:date>2026-02-09T23:29:16Z</dc:date>
    <item>
      <title>EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351353#M599153</link>
      <description>&lt;P&gt;Hello Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This looks interesting to me. For Authz rule it never matches the 1st rule. After device is booted and before user logged in i see at ISE EAP Chaining result is User Failed but Machine Succeeded &amp;amp; it matches the 2nd Authz rule and then when user logs in i see User Succeeded and Machine succeeded and matching the same Authz rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I should see 2 Authz match - Can you advise what I am missing&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSJ1_0-1764616804016.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/256093i2B498020F07E7D3E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MSJ1_0-1764616804016.png" alt="MSJ1_0-1764616804016.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;AuthZ Policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSJ1_1-1764616857805.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/256094i51F7FFB85DA32E4F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MSJ1_1-1764616857805.png" alt="MSJ1_1-1764616857805.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 19:27:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351353#M599153</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-12-01T19:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351400#M599158</link>
      <description>&lt;P&gt;The policy looks pretty basic, so something is not matching in the top rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would assume it's the user group match, but you can confirm that by removing that matching condition.&lt;/P&gt;
&lt;P&gt;At that point, you would need to look at the detailed Live Logs to confirm that the User credential is being sent in UPN format, that ISE is using that credential for identity, and that the membership group ID matches what you see in Entra ID.&lt;/P&gt;
&lt;P&gt;If all of the above is true, then you might need to open a TAC case to investigate further why the condition is not matching.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 21:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351400#M599158</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-12-01T21:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351411#M599159</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I disable rule 2 from the screenshot and as I said it does not match the rule 1 and it matches deny authz on that log I see&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on PremisesUserPrincipalName is BLANK&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSJ1_0-1764628362695.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/256105i59822DDF87984ECF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MSJ1_0-1764628362695.png" alt="MSJ1_0-1764628362695.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But on same Auth Fail log I see "User Succeeded and Machine Succeeded"&lt;/P&gt;
&lt;P&gt;in CAP for field - Use Identity From - I am using Certificate Attribute - Subject Common Name. From common name it should be able to read UPN.&lt;/P&gt;
&lt;P&gt;Any more clue plz&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 22:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351411#M599159</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-12-01T22:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351413#M599160</link>
      <description>&lt;P&gt;From the REST ID Entra ID Integration - I removed - User Attribute - onPremisesUserPrincipalName and added&amp;nbsp;UserPrincipalName , now in the failed log I see UPN field but still not working&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 22:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351413#M599160</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-12-01T22:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351802#M599178</link>
      <description>&lt;P&gt;There is nowhere near enough detail here to provide any meaningful assistance, nor is there any indication that the prior suggestions have been followed. See&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank" rel="noopener"&gt;How to Ask the Community for Help.&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Call TAC to investigate&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 21:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5351802#M599178</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-12-02T21:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352188#M599209</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;after removing the Entra AD Group it matches user succeeded and machine succeeded policy when user logs in. Interesting is if I call an Old AD Group where the same user is&amp;nbsp;it matches the user&amp;nbsp;user succeeded and machine succeeded policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason ISE is not able to lookup the user when a newly created Entra Group is called as part of user Authz rule.&lt;/P&gt;
&lt;P&gt;Both working and non working Entra group I can add from REST ID Section &amp;gt;&amp;gt; User group and User Attribute is UPN.&lt;/P&gt;
&lt;P&gt;in the debug log it shows - it is not able to fetch the non working group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My understanding it matches this bug -&amp;nbsp;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwd34467" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCwd34467&lt;/A&gt;&amp;nbsp;, however here ise version is 3.5&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 00:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352188#M599209</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-12-04T00:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352287#M599214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Your authorization policies matching criteria don't look right. Follow this document and if you still don't have it working afterwards, past print-screens of ISE Authentication Details for both machine and user/machine steps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 09:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352287#M599214</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2025-12-04T09:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352563#M599221</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;For some reason ISE is not able to lookup the user when a newly created Entra Group is called as part of user Authz rule."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This sounds more like some sort of role/permission issue on the group or something else on the Entra side. I use Entra only groups (as opposed to hybrid AD groups) all the time and have never seen this behaviour.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would suggest confirming that these are Security Groups (not Microsoft 365 Groups), confirm if there is any difference in the assignment type (direct, dynamic, etc), and review the relevant logs on the Entra ID side.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You could try opening a TAC case, but considering you've already looked at the ISE debug logs, they may suggest you open a case with Microsoft to check the Entra side anyway.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2025 00:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5352563#M599221</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-12-05T00:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining Both Authz Rule Not Matching</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5368872#M599762</link>
      <description>&lt;P&gt;Unfortunately this issue is related to&amp;nbsp;&lt;SPAN class="custom-text-color-light subheader-large"&gt;CSCws30603 (&amp;nbsp;&lt;SPAN class="subheader-large"&gt;ISE unable to fetch user group membership if user belongs to more than 20 groups ).&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="custom-text-color-light subheader-large"&gt;&lt;SPAN class="subheader-large"&gt;Is there time line can someone share when this bug will be resolved&amp;nbsp; ? for version 3.5.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="custom-text-color-light subheader-large"&gt;&lt;SPAN class="subheader-large"&gt;What are the workarounds if we cannot use Device/User GroupMembership due to this bug to use in AuthC and AuthC Profile ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="flex flex-left flex-wrap"&gt;
&lt;DIV class="base-margin-right"&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 09 Feb 2026 23:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-both-authz-rule-not-matching/m-p/5368872#M599762</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2026-02-09T23:29:16Z</dc:date>
    </item>
  </channel>
</rss>

