Authorization policy for only domain computers

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2018 03:37 AM
Hi Cisco
I need help to setup Policy for authorization to the network only for domain computers.
I have connected MS Domain controller to the ISE and using for username and password checking.
I would setup additional Authorization policy that only computer joined to domain able to pass and join to the corporate network.
Also I would know how to setup Certificate authorization policy so only computers that have certificate from the Domain controller can pass this step of authorization.
Best regards,
- Labels:
-
Identity Services Engine (ISE)

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2018 04:28 AM
Please take a look here Cisco ISE Wired Access Deployment Guide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2018 05:57 PM
Take a look at
- [ISE Lab Guide] ISE Active Directory Integration
- How To: ISE & BYOD: Using Certificates For Differentiated Access
Essentially, the authentications will be based on certificate using a certificate authentication profile to specify the certificate field to be used as the identity for authorization, and the authorization will perform AD group lookup.
