cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
390
Views
0
Helpful
1
Replies

BYOD "trusted" Device workflow

ggriesse@cisco.com
Cisco Employee
Cisco Employee

Hi all 

 

customer has a requirement to use certificates to trust BYOD devices on their network with ISE - Contractors bring in there own machines and have AD accounts for Auth .. 

 

They have tested "device on-boarding" workflows with ISE However have hit a few stumbling blocks 

 

1) they don't believe that using a username/password to then use SCEP to issue a cert is secure enough ...

2) We have tested using temporal agent to validate some checks for the BYOD devices to add a further level of validation however one of the checks they need to validate is disk encryption check - and temporal agent doesn't support this ....

 

3) they need to support , Windows , Mac and Linux machines 

 

4) they know we have workflows in Guest for Sponsor approval and have asked if we can do something similar for BYOD validation .. ie allow the byod machine to auth with AD credentials , BUT then only get a cert issued once "approved" 

 

Any ideas guys ? 

1 Accepted Solution

Accepted Solutions

kvenkata1
Cisco Employee
Cisco Employee

Please refer to the BYOD deployment guide.

https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867

 

Any other flow that is different from what is documented above needs to be addressed by our PM team as new feature.

 

- Krish

View solution in original post

1 Reply 1

kvenkata1
Cisco Employee
Cisco Employee

Please refer to the BYOD deployment guide.

https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867

 

Any other flow that is different from what is documented above needs to be addressed by our PM team as new feature.

 

- Krish