cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1510
Views
0
Helpful
1
Replies

Cisco ACS - Additional Attribute Retrieval Search List in Users and Identity Stores

umahar
Cisco Employee
Cisco Employee

I am trying to understand the behaviour and usage of "Additional Attribute Retrieval Search List" under Identity Store Sequence in ACS ? In ISE we can choose only one Identity Store in identity store sequence but in ACS it gives us an option to choose another external identity source to retrieve additional attributes.

This is being highlighted in an ACS to ISE migration engagement.

This is another thread referring to the same feature.

https://community.cisco.com/t5/other-security-subjects/cisco-acs-additional-attribute-retrieval-search-list-in-users/m-p/3755853#M148548

1 Reply 1

hslai
Cisco Employee
Cisco Employee

The main difference is that ACS checks only the attributes in this list while ISE checks anything specified in the authorization policy rules during evaluation.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: