cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
455
Views
0
Helpful
1
Replies

Cisco ISE 3.2 Patch 4 Single Click Approval Not Working with AD

jack.warmya
Level 1
Level 1

hello folks,

I am trying to implement the One-Click approval solution with the guide provided by Jason Kunst. However it is not working for me.

https://community.cisco.com/t5/security-knowledge-base/ise-single-click-sponsor-approval-faq/ta-p/3637016/page/2

My AD is registered in ISE, and is a part of the identity source sequence. The users are also part of AD.
• Sponsor user AD Domain: D01.company.local
• Sponsor email address: firstname.lastname@company.com
• Sponsor user in AD has the email attribute that matches with the email “person being visited”

First issue:

When the guest user self registers, the sponsor receives the email to Approve or Deny.  The sponsor clicks "Approve", however it still brings the sponsor to the sponsor portal and ask the sponsor to authenticate in order to validate the user request.

Second issue:

Once the sponsor does authenticate, the guest sees the approval go through on their screen.  After accepted the AUP and it redirects them to our company page. 

However, the sponsor receives a web page that says, "Link is invalid. Please sign on to the sponsor portal to approve/deny guests."; even though the guest has already been approved.

Have you experienced the similar issues ?

Thanks,

 

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

@jack.warmya, The links to single click approve self-registered guest users are good for 3 hours only and they are also specific to the host IP address or the FQDN of the specific sponsor portal. Please review the video ISE Single Click Sponsor Approval Feature Overview; especially, ~ 7 minutes onwards in the video.

In case that does not help, please engage Cisco TAC support to take a look at your deployment scenario and troubleshoot further.

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

@jack.warmya, The links to single click approve self-registered guest users are good for 3 hours only and they are also specific to the host IP address or the FQDN of the specific sponsor portal. Please review the video ISE Single Click Sponsor Approval Feature Overview; especially, ~ 7 minutes onwards in the video.

In case that does not help, please engage Cisco TAC support to take a look at your deployment scenario and troubleshoot further.