So, I might be interested in using the local ID store, since I have no more than 150 wired users at an given time. The upfront work of putting in those users would still be better than manually configuring ports.
I see "External Identity Sources" under "Administration," but where is the local identity store. Also, if going this route, how does it work? Would a user have to put in credentials twice, once for ISE, then again for LDAP?
Edit:
I've done some digging and learned where the local users are stored. It would appear I can have the internal users leverage LDAP for passwords. This is helpful. A question that remains is, how does the "Internal Users" option in Policy Sets tie back to the users I've added to network access users?