06-21-2019 07:38 AM - edited 06-21-2019 08:01 AM
I am doing a guest install where the guest PSNs are not joined to AD and we are using LDAP. We have an group mapped into to the sponsor role and the users can log into the sponsor portal without an issue using their account name (JDoe4567 as an example). The user's email address is jdoe@customer.com. Because they are doing O365 they have changed all their UPNs to jdoe4567@customer.com. The only LDAP attribute that has the email address in it is the Mail attribute.
When the guest enters jdoe@customer.com in as the person they are visiting the sponsor receives an email but has to sign into the portal which means the single click process didn't work. We set this up in a lab as well and changed the UPN to jdoe@customer.com and single clicked worked perfectly.
Is ISE only looking up the UPN attribute when it does the single click look-up based on the email address?
Solved! Go to Solution.
06-24-2019 01:57 PM
06-21-2019 08:01 AM
An update, we turned on some debugs and we can see in the guest.log that the email lookup is working against LDAP but it says no groups are received. The same account though works when we sign into the sponsor portal so LDAP groups are working there.
06-24-2019 01:53 PM
06-24-2019 01:57 PM
06-28-2019 08:33 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide