Hello,How can I check if an username retrieved from the certificate common name belongs to a specific AD group? In the policy set I can match against the general AD as an external group object (have a look at the attached screenshot) so ISE performs ...