- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2020 02:24 PM
I've been told this isn't possible but want to check. Planning to deploy ISE 2.7. For the same SSID, is it possible to use computer auth for some clients and user auth for different clients?
For example, our domain joined windows 10 machines, I'd prefer to use computer auth. This helps with group policy running and allows a network connection prior to windows login. I'd like the same for domain macOS devices.... For our iPADs, they'd need user auth, as they won't have the certificate.
We don't have anyconnect client
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-22-2020 09:15 AM
Both are easily possible.
See ISE Authentication and Authorization Policy Reference > Microsoft Active Directory Groups Authorizations for examples of each.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2020 04:38 PM
authentication will be as you need. So w10 and mac profiled machines can
use machine auth.
Use device sensors on the switches to send attributes to ISE for profiling.
***** please remember to rate useful posts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2020 05:25 PM
would that require that I have Plus licensing? I only will have base licensing to start
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-22-2020 04:50 AM
yes you need for additional requirement :
here is good license document explained - what feature cover based on the model

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-22-2020 09:15 AM
Both are easily possible.
See ISE Authentication and Authorization Policy Reference > Microsoft Active Directory Groups Authorizations for examples of each.
