cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2015
Views
1
Helpful
4
Replies

Manually adding endpoints to RegisteredDevices

GQ
Cisco Employee
Cisco Employee

Looks like registered BYOD endpoints were purged because of the default 30 day policy for a PoV.  Tried to manually put their MACs back into the RegisteredDevices endpoint group (instead of 'profiled') but for some reason they still failed the Authentication because the group didn't match the policy step.  Is this method supported?

Other endpoints we had them manually forget the SSID, rejoin via PEAP and kickoff another onboarding flow (acquiring certs).  It would be great if we could manually put macs back into the group instead of that.

image002.png

1 Accepted Solution

Accepted Solutions

Thomas Wall
Cisco Employee
Cisco Employee

Gary,

Is your AuthZ rule looking for the endpoint in the RegisteredDevices group or are you trying to match on the BYOD flag for Device Registration?  If the latter, can you try a bulk import of those devices and make sure you set the BYODRegistration status to Yes?

During the bulk import, new endpoints are added along with the defined attributes whereas existing endpoints will be updated. When you manually add the endpoint, you are not given the option to set the BYODRegistration field.

-Thomas

View solution in original post

4 Replies 4

Thomas Wall
Cisco Employee
Cisco Employee

Gary,

Is your AuthZ rule looking for the endpoint in the RegisteredDevices group or are you trying to match on the BYOD flag for Device Registration?  If the latter, can you try a bulk import of those devices and make sure you set the BYODRegistration status to Yes?

During the bulk import, new endpoints are added along with the defined attributes whereas existing endpoints will be updated. When you manually add the endpoint, you are not given the option to set the BYODRegistration field.

-Thomas

Yes we were matching on the BYOD flag.  I'll test that out.

Would the endpoint purge clear this flag?  Seems like it would if the endpoint is gone.

Yes it would

GQ
Cisco Employee
Cisco Employee

Thanks all