cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1002
Views
0
Helpful
6
Replies

Guest Pending Account Purge

paul
Level 10
Level 10

What setting in ISE controls the purging of pending guest accounts?  I am doing single click guest acceptance.  I know I can control how long the single click link is good for, but if sponsor doesn't approve the guests and they Pending list just continues to grow, what setting purges that out?

I know there is the "Expire portal-user information after:" setting.  Does that setting affect pending accounts? Or is there any way just to target the pending guest list?

I am sure I am just missing it in the documentation.  Jason, you can RTFM me.

Thanks

1 Accepted Solution

Accepted Solutions

Quickly found this, 2.2 has under work centers guest access and has slightly changed

Check the 2.2 doc of same and look at the UI

http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_01110.html

View solution in original post

6 Replies 6

Charlie Moreton
Cisco Employee
Cisco Employee

Have you tried through the Sponsor Portal?

Pending.PNG

Ohh I know I can do it through the sponsor portal, but looking for a way to purge automatically, i.e. if pending guest account is not approved or denied in 3 days remove it from the system.

Paul Haferman

Office- 920.996.3011

Cell- 920.284.9250

Quickly found this, 2.2 has under work centers guest access and has slightly changed

Check the 2.2 doc of same and look at the UI

http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_01110.html

Yes the screen I was looking at was:

It is just unclear is any of those settings apply to Pending Accounts. I think unused guests may work. I will have to run some tests.

Paul Haferman

Office- 920.996.3011

Cell- 920.284.9250

The documentation Ive read only speaks of expired accounts or denied accounts, though pending guest accounts seem to just keep growing and growing unless manually deleted or denied. I'd also like these to be automatically purged as well with the expired & denied accounts. Is this possible or is this just a manual process for now?

This is an old thread, perhaps you want to start new one? Regardless, What version of ise are you using? For best guest functionality you should at least be on 2.4 (2.6 is current recommended version now) I am pretty sure that newer recommended versions of ISE have cleaned this up. It’s even mentioned in the UI under guest purge settings.

https://community.cisco.com/t5/security-news/announcing-ise-2-6-as-suggested-release/ba-p/3953488