cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
866
Views
0
Helpful
3
Replies

Device Admin Internal Groups are not available

kai.onken
Level 1
Level 1

Good Moring,

 

After I added successfully some User Identity Groups by using "Work Centers -> Device Administration", I added some Local Identities to those Groups. The Policy Elements have also been added.

 

When I now try to add "Device Admin Policy Sets" happens this. I add a new Policy Set, added a policy name, added as an condition the locations of the devices and selected "Default Device Admin" and saved the policy set.

After Saving I pressed View button ">", opend Authentication Policy and set the Default value to "Internal Users" and save the Policy Set successfully.

Then I opend the Authorization Policy Tab, defined a rule name, selected my command set and shell profiles. Up to this point everything works fine.

Now my Problem starts: When I press "+" to add a new condition, normally I should be able to select my "User Identity Groups", I created before. But no "User Identity Groups" groups are vailable. But why:

 

ISE Version: 2.3

AD Join: Yes, Windows Server 2012 R2

Licence: Device Administration, Endpoint

 

Many thanks and kind regards

Kai

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

What patch level are you running? There were several bugs in ISE 2.3 (unpatched) that relate to Policy Studio. Most notably for your case I'd suspect:

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf87440 (fixed in Patch 2).

 

In general I recommend 2.4 (currently at patch 1) over 2.3 since 2.4 will be a long term support release.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

What patch level are you running? There were several bugs in ISE 2.3 (unpatched) that relate to Policy Studio. Most notably for your case I'd suspect:

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf87440 (fixed in Patch 2).

 

In general I recommend 2.4 (currently at patch 1) over 2.3 since 2.4 will be a long term support release.

Thanks, for the tip. This was the solution on one side. The other point I forgot, was that on the left side, when you "build" a compound conditon, you can used previous save conditions and I was wondering, why I can't see here the conditions I've used. I haven't saved them for future use.

 

Thanks and kind regards

Kai

@kai.onken thanks for the feedback and the rating.