cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12467
Views
21
Helpful
8
Replies

How do I authenticate users in a specific AD group with Cisco ISE

I have ISE up and running authenticating properly.  But right now it will authenticate and allow ANY account in Active Directory.  I want to allow access to only users in a specific group in Active Directory.  I have added the group under Administration>Identity Management>External Identity Sources>Active Directory>Groups.  But, I have not been able to find a way to link membership in that group to the Authentication Policy rules.

2 Accepted Solutions

Accepted Solutions

Under your Authorization policy, when you add the condition, choose the advanced option, there you should see an option for AD (select that) then the ExternalGroup option should appear. Set that attribute option equal to the AD group you are after.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

Chris,

I dont know where you are with the screenshot but follow this path:Policy > Authorization > (on the rule you want to limit AD group access) Select Attribute > Create New attribute (Advanced) the AD option should appear there. Currently the box i am using isnt joined to AD so I can't show you how it looks.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

8 Replies 8

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

You will have to add the group in you AD settings.

Then you can map that group in you authorization profile.

Thanks


Sent from Cisco Technical Support Android App

Yes, I understand that.  I have added the group in AD settings. 

What I need to know is HOW do I map that group to the auth profile?

Under your Authorization policy, when you add the condition, choose the advanced option, there you should see an option for AD (select that) then the ExternalGroup option should appear. Set that attribute option equal to the AD group you are after.

Thanks,

Tarik Admani
*Please rate helpful posts*

Thanks for the reply.

I'm not getting AD as an option (see below).  Any idea why that might be?

Chris,

I dont know where you are with the screenshot but follow this path:Policy > Authorization > (on the rule you want to limit AD group access) Select Attribute > Create New attribute (Advanced) the AD option should appear there. Currently the box i am using isnt joined to AD so I can't show you how it looks.

Thanks,

Tarik Admani
*Please rate helpful posts*

Thank you very much.  That was the step I was missing.  It works the way I want it to now.

Disregard above.  I was looking in Authentication not Authorization rules. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: