<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding Posture Agentless Authz policies on a working TEAP Eap-chai in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5545574#M600251</link>
    <description>&lt;P&gt;Just curious on the reason for Agentless Posture? Why not use MDM-based posture instead? Agentless requires a lot of negative security nuances on the endpoint and is an overall horrible user experience.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Apr 2026 16:18:38 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2026-04-15T16:18:38Z</dc:date>
    <item>
      <title>Adding Posture Agentless Authz policies on a working TEAP Eap-chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5544015#M600200</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I have a working LAB environment with ISE 3.3 (Patch 10) and Windows 11 Endpoint with Windows Native Supplicant. This is using TEAP (EAP-TLS) for both machine and user authentication using certificates (machine certs + user Certs already deployed in the endpoint). By using TEAP, we are using EAP-Chaining. This is working fine with no issues.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;From this base working environment, we want to add "Agentless posture" checks, but this is failing, showing as "non compliant" posture result, but the posture policy check we are doing is just Application visibility (default App visibility on ISE) to have an inventory of the applications.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I modified the working simple authz policies to adapt the "Agentless Posture" states (non compliant, compliant, unknown) following the generic implementation guide from this link:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-agentless-posture-configuration-validation-amp/ta-p/4152763#toc-hId-1900740336" target="_blank"&gt;How To: Agentless Posture Configuration, validation &amp;amp; Troubleshooting - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;U&gt;&lt;STRONG&gt;Working environment policies and logs (before enabling Agentless Posture)&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. ISE Authorization Policies using TEAP (EAP-TLS) for machine, and machine + user authorization (EAP-chaining)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Authz Policy 1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280182iE4EA838676D08BFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Authz Policy 1.png" alt="ISE Authz Policy 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorCarlosT_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;2. On ISE Radius Live Logs, we see both Authorization policies are hit first when the PC is connected (machine authz only), and then, when the user logs in (machine + user authz) via EAP Chaining.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Logs 1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280183i8694AEA02AF06C29/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Logs 1.png" alt="ISE Logs 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;U&gt;&lt;STRONG&gt;New Updated Authorization policies to support Agentless Posture and logs (After enabling Agentless Posture)&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;OL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11.0pt; font-weight: bold; font-style: normal;" type="1"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; font-weight: bold;" value="1"&gt;ISE Authorization Policies supporting Agentless posture:&lt;/LI&gt;
&lt;OL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11.0pt; font-weight: bold; font-style: normal;" type="a"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; font-weight: bold;" value="1"&gt;3x Top Policies for the 3 possible posture states (no compliant, compliant, unknown) for machine + user authorization (EAP-chaining)&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; font-weight: bold;"&gt;1x Bottom Policy for the very first time the machine is connected to the network (matching only user failed + machine succeeded). The result profile on this rule has the "Agentless" option selected to force the agentless process to trigger.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Authz Policy 2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280184i3C996428ADBA536B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Authz Policy 2.png" alt="ISE Authz Policy 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Authz Policy 2-a.png" style="width: 601px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280185iA68299C59D5272CC/image-dimensions/601x317?v=v2" width="601" height="317" role="button" title="ISE Authz Policy 2-a.png" alt="ISE Authz Policy 2-a.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;2. On ISE Radius Live Logs, we see the firs time the PC is powered on (before user login), that the Authorization policy (bottom on the list) is hit and this is for user failed+machine succeded and using the result profile of Agentless Posture. This is fine and expected. Then when the user log in, it hits the "non compliant" posture status (matching the rule "Agentless Posture non compliant").&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Logs 2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280186iEB2FB43065648035/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Logs 2.png" alt="ISE Logs 2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;From the detailed radius log view, the following is taking my attention, but no sure if seeing this "duplicate session" message below the posture check message is normal or is an indication of an issue that has something to do with the posture? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Logs 2-a.png" style="width: 412px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280187i6E3EE8896FBBF789/image-dimensions/412x255?v=v2" width="412" height="255" role="button" title="ISE Logs 2-a.png" alt="ISE Logs 2-a.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;The host is shown in "context visibility"&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Logs 2-b.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280188i3019AA6DB1A255E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Logs 2-b.png" alt="ISE Logs 2-b.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;No Applications are visible&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE Agentless Posture.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280189i0756E4C13BB23935/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Agentless Posture.png" alt="ISE Agentless Posture.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Posture Policy is only application visibility&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Posture_Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280190i7DB9A549A3383A26/image-size/large?v=v2&amp;amp;px=999" role="button" title="Posture_Policy.png" alt="Posture_Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Posture Requirements&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Posture_req1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280192iB63ADA08C2860947/image-size/large?v=v2&amp;amp;px=999" role="button" title="Posture_req1.png" alt="Posture_req1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Posture_req2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280191i807E16AFEECDD9AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Posture_req2.png" alt="Posture_req2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Posture condition&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Posture_app_conditions.png" style="width: 956px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280193iEBC44A4095957C4F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Posture_app_conditions.png" alt="Posture_app_conditions.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;After restarting ISE we see this time it is stuck on "pending" posture status.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs_after_ise_restart1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280194i7F9D47C225DAADC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs_after_ise_restart1.png" alt="logs_after_ise_restart1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs_after_ise_restart2.png" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/280195iF8F58AD78264E9B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs_after_ise_restart2.png" alt="logs_after_ise_restart2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;As shown on the implementation guide, we enabled all the requirements on the endpoint, like Enabling remote power shell, allowing the firewall rule for inbound connection from ISE, and installing Power Shell 7.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2026 13:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5544015#M600200</guid>
      <dc:creator>Carlos T</dc:creator>
      <dc:date>2026-04-08T13:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Posture Agentless Authz policies on a working TEAP Eap-chai</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5545574#M600251</link>
      <description>&lt;P&gt;Just curious on the reason for Agentless Posture? Why not use MDM-based posture instead? Agentless requires a lot of negative security nuances on the endpoint and is an overall horrible user experience.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 16:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5545574#M600251</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2026-04-15T16:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Posture Agentless Authz policies on a working TEAP Eap-chai</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5546289#M600271</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;. Can you share what of the "negative security nuances on the endpoint" you have experienced?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 18:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5546289#M600271</guid>
      <dc:creator>Carlos T</dc:creator>
      <dc:date>2026-04-17T18:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Posture Agentless Authz policies on a working TEAP Eap-chai</title>
      <link>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5546292#M600273</link>
      <description>&lt;P&gt;All of this: "like Enabling remote power shell, allowing the firewall rule for inbound connection from ISE, and installing Power Shell 7." Also the local accounts required for agentless.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 19:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adding-posture-agentless-authz-policies-on-a-working-teap-eap/m-p/5546292#M600273</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2026-04-17T19:00:11Z</dc:date>
    </item>
  </channel>
</rss>

