cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
443
Views
2
Helpful
4
Replies

How to use active directory “extension Attribute” in ISE policy

JustTakeTheFirstStep_0-1739329231681.png

We want to create a policy set in ISE from an extension Attribute value in AD.

Can we use that attribute in the Policy Condition in ISE?

Any ideas?

 

3 Accepted Solutions

Accepted Solutions

Arne Bier
VIP
VIP

Have you had a look in your AD joined ISE?  You can easily check this by navigating to Administration > Identity Management and then clicking on your AD Join Point. Open the 'Attributes' tab and then click 'Add'

ArneBier_0-1739330414974.png

Then I tend to select the option 'Select Attributes from directory' and give it a username as an example. I don't know if these extensions should exist in my AD - but I don't see them. Maybe you see them in your ISE.

ArneBier_1-1739330553045.png

 

Failing that, you can also bind ISE to your AD controllers using LDAP and then you will have complete access to all the objects. 

 

 

 

 

 

View solution in original post

Edit/create the Rule, and then click on the Conditions field to open up the Editor

 

You can search in the AD Join Points. Under the Dictionary drop-down, look for you AD Join Point name - e.g.

ArneBier_1-1739335775554.png

 

 

ArneBier_0-1739335599406.png

 

 

 

View solution in original post

4 Replies 4

Arne Bier
VIP
VIP

Have you had a look in your AD joined ISE?  You can easily check this by navigating to Administration > Identity Management and then clicking on your AD Join Point. Open the 'Attributes' tab and then click 'Add'

ArneBier_0-1739330414974.png

Then I tend to select the option 'Select Attributes from directory' and give it a username as an example. I don't know if these extensions should exist in my AD - but I don't see them. Maybe you see them in your ISE.

ArneBier_1-1739330553045.png

 

Failing that, you can also bind ISE to your AD controllers using LDAP and then you will have complete access to all the objects. 

 

 

 

 

 

Okay. How do i then use that attribute as a condition in an authorization policy?

Edit/create the Rule, and then click on the Conditions field to open up the Editor

 

You can search in the AD Join Points. Under the Dictionary drop-down, look for you AD Join Point name - e.g.

ArneBier_1-1739335775554.png

 

 

ArneBier_0-1739335599406.png

 

 

 

JustTakeTheFirstStep_1-1741668323100.png

JustTakeTheFirstStep_0-1741668235351.png