03-24-2025 04:04 AM
Dear All,
i need some help,i need to auth only the domain computer any one not join domain and plug the cable to switch will not auth
03-24-2025 04:07 AM
Use EAP-TLS and certificates.
https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356
03-24-2025 04:13 AM
i`m using EAP-TLS for user`s Authentication , but i need to know how can i authenticated only the PC`s join domain
03-24-2025 04:24 AM
Well if the endpoint has a certificate from your PKI they are probably already on the domain no?
You can do a binary comparison in the CAP or in the Authorization policies, check that the endpoint is a member of Domain Computers.
03-24-2025 04:59 AM - edited 03-24-2025 04:59 AM
Hi,
If you are using ISE, you can use the attribute below in your authorization profile:
Network Access:WasMachineAuthenticated ==True
04-07-2025 12:22 AM
But take care with using the attribute Network Access:WasMachineAuthenticated ==True as it may happen that MacOS users won't be authorized as the machine authentication is not passed.
04-07-2025 05:43 AM
You can create authorization rule where you put a condition to match if the machine is part of "Domain Computers" or similar group in Active Directory. You can refer multiple groups to include all the domain joined endpoints.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide