04-08-2025 09:08 PM
I’m currently using Cisco ISE with Passive Identity (PassiveID) configured to collect user login data via PICAgent installed on DCserver. However, I’ve noticed that the Cisco ISE Showing Service/Application Logons Cisco ISE Showing Service/Application Logons(remote interactive/RDP). These reflect real users logged into the PC, which is what we want to track for accurate identity mapping.
04-08-2025 10:47 PM - edited 04-09-2025 10:07 PM
Hello!
Cisco ISE with PassiveID using PICAgent on your DCserver is correctly tracking remote interactive/RDP logons, which is a normal and beneficial aspect of passive identity collection for accurate user-to-IP mapping. This allows for identity-based policies for RDP users. If you have a tollbyplate com specific question or issue regarding these RDP logon events, please provide more details. Otherwise, this behavior indicates your PassiveID setup is functioning as designed for remote sessions.
04-08-2025 10:59 PM
Hello,
Actually ISE is also showing up Service/Application(Outlook,NMS) Logons which is not required i only needed interactive/RDP logons event
04-09-2025 01:30 AM
currently using Cisco ISE with Passive Identity (PassiveID) configured to collect user login data via PICAgent installed on DC server. However, I've noticed that the Live Sessions section in ISE is showing sessions for service and application logons, including accounts used by applications such as Outlook or NMS tools.
My requirement is to see only actual user interactive logins, specifically Logon Type 2 (local interactive) and Logon Type 10 (remote interactive/RDP). These reflect real users logged into the PC, which is what we want to track for accurate identity mapping.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide