cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
638
Views
0
Helpful
1
Replies

Apply SGT based on PolicyID Group?

blroberts2
Level 1
Level 1

We have ISE 2.3 up to replace CDA for our WSA solution.  PassiveID is working and pulling all user<>IP mappings and seeing the groups.  We need to apply our created SGTs solely based on the PassiveID / AD groups from the users and are not having any luck.  We've seen some documentation for older ISE versions but cannot recreate it in 2.3 with Policy Sets on.

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

CDA and ISE Passive ID cannot assign an SGT today without a RADIUS authorization.  External solutions can still leverage AD group info sent in log or pxGrid updates.

View solution in original post

1 Reply 1

Craig Hyps
Level 10
Level 10

CDA and ISE Passive ID cannot assign an SGT today without a RADIUS authorization.  External solutions can still leverage AD group info sent in log or pxGrid updates.