08-14-2018 06:49 AM
Hi team,
Just as a sanity check, consider the scenario where we have multiple users (both admin and non-admin) in Windows running on the same machine. If a non-admin user runs the browser as an admin and follows the BYOD flow, is it possible for the non-admin user to install the BYOD cert?
Also, if an admin user (after having completed the BYOD flow) authenticates against ISE using the cert, and then using fast user switching a non-admin user logs in (without sending any EAPOL logoff message). Will the non-admin user be able to reuse the existing authenticated session from the admin user?
Thanks,
Oriol
Solved! Go to Solution.
08-14-2018 07:02 AM - edited 08-14-2018 07:03 AM
Non-admin user won't be able to complete the BYOD flow as it requires running executable and also access to the certificate store. In the fas-user-switching, yes what you describe is correct, since the first user did not log off, from the network perspective, the first user is still logged in.
08-14-2018 07:02 AM - edited 08-14-2018 07:03 AM
Non-admin user won't be able to complete the BYOD flow as it requires running executable and also access to the certificate store. In the fas-user-switching, yes what you describe is correct, since the first user did not log off, from the network perspective, the first user is still logged in.
08-14-2018 07:33 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide