04-10-2026 02:01 AM
Hello everyone, I currently have a question regarding the Compound condition feature in Cisco ISE.
Suppose I have two conditions:
If I configure a compound rule combining these two conditions using an AND operator, does that mean the conditions will be evaluated sequentially?
Is there a way to combine them using a compound condition so that the AV check is evaluated first, followed by the Windows patch check? In other words, if condition 1 (AV check) matches, the device will be blocked immediately without evaluating condition 2 — is that possible?
04-10-2026 03:06 AM - edited 04-10-2026 03:07 AM
@tronnq hi, policies are running from top to bottom. in this case i suggest you use condition 2 as 1st policy with 'OR' operator with condition 1 as second policy.
04-15-2026 12:50 AM
Hi,
This is my situation, we have 2 posture policy as image, rule check_patch have grace periods. If we check posture on machine, policy always allow connection for grace periods. Even though the version on that machine is wrong and AV is missing.
04-15-2026 09:14 AM
Why not use MDM-based posture instead?
04-15-2026 07:24 PM
Hi bro, I’m trying to verify whether this is a limitation of ISE. Because when checking these two conditions, ISE always prioritizes the grace period, even though both conditions on the device are failed.
04-15-2026 11:52 PM
Hi guy,
I see on the ISE has Dictionary Attributes -> posture, but why I can see it in configure authorization policy?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide