cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

445
Views
5
Helpful
1
Replies
ryan14
Beginner

How to block a profiled device

I am trying to block mobile phones from a policy. The issue is that If I look at my authz policy and go to 'Identity Group-Name' EQUALS I don't see all profiled built-in groups. For example, my phone that gets profiled Apple-Device, where does that map to in ISE via policy? I do see in Endpoint Identity groups, Apple-iDevice. But if I set that to block in my authz policy, it doesn't match. Is there a way to block a Profiled group or policy that equals Apple-Device?

 

Is there a way to add a group of profiling policies and then apply that to a policy set? Such as group Apple-Device, Android-*, etc and apply that to the policy block?

 

Thanks.

1 ACCEPTED SOLUTION

Accepted Solutions
Damien Miller
VIP Advisor

The difference is that the built in profiles are not the same as identity groups, they certainly can be mapped to identity groups if you enable "create matching ID group" within the profile, but most do not by default. What you're after here to use in the authz is "EndpointPolicy" which is the profile you see, or you can use "logicalProfile" if you have grouped any profiled in a logical group or profiles. 

profile.JPG 

View solution in original post

1 REPLY 1
Damien Miller
VIP Advisor

The difference is that the built in profiles are not the same as identity groups, they certainly can be mapped to identity groups if you enable "create matching ID group" within the profile, but most do not by default. What you're after here to use in the authz is "EndpointPolicy" which is the profile you see, or you can use "logicalProfile" if you have grouped any profiled in a logical group or profiles. 

profile.JPG 

View solution in original post

Content for Community-Ad