Cisco ACS - Additional Attribute Retrieval Search List in Users and Identity Stores

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2019 09:22 AM
I am trying to understand the behaviour and usage of "Additional Attribute Retrieval Search List" under Identity Store Sequence in ACS ? In ISE we can choose only one Identity Store in identity store sequence but in ACS it gives us an option to choose another external identity source to retrieve additional attributes.
This is being highlighted in an ACS to ISE migration engagement.
This is another thread referring to the same feature.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-29-2019 09:48 AM
The main difference is that ACS checks only the attributes in this list while ISE checks anything specified in the authorization policy rules during evaluation.
