cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
 
Register for the monthly ISE Webinars to learn about ISE configuration and deployment.
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

79
Views
0
Helpful
2
Replies
Beginner

Does all the AD attributes gets updated for every authentication?

Our desktop team is upgrading W7 to W10 and after upgrading the old W7 to W10 I have observed on ISE 2.4 some of the attributes still reflects the old W7 machine and hence the machine won't get profiled accurately.

Stale attribute example being AD-Fetch-Host-Name, AD-Operating-System, AD-Service Pack, FQDN and other attributes such as User-Fetch-User-Name, host-name gets updated to match W10.

The only workaround I see is to delete an endpoint and have it reauthenticated to see all the updated attributes. 

Any other recommendations?

 

 

2 REPLIES 2
Beginner

Re: Does all the AD attributes gets updated for every authentication?

How long are you waiting before checking for updated AD attributes?  In the node profiling configuration there is a box to set the number of days before rescan.  I believe the default is 1 day, so it could be a day or so before you would see updated values depending on the timing of when ISE queries AD and when the endpoint was imaged. 

Beginner

Re: Does all the AD attributes gets updated for every authentication?

@packetplumber9  I am waiting for enough time. Also, the machine AD attribute "AD-Last-Fetch-Time" displays todays time. 

 

Thanks!!