02-11-2025 07:02 PM - edited 02-11-2025 07:03 PM
We want to create a policy set in ISE from an extension Attribute value in AD.
Can we use that attribute in the Policy Condition in ISE?
Any ideas?
Solved! Go to Solution.
02-11-2025 07:23 PM
Have you had a look in your AD joined ISE? You can easily check this by navigating to Administration > Identity Management and then clicking on your AD Join Point. Open the 'Attributes' tab and then click 'Add'
Then I tend to select the option 'Select Attributes from directory' and give it a username as an example. I don't know if these extensions should exist in my AD - but I don't see them. Maybe you see them in your ISE.
Failing that, you can also bind ISE to your AD controllers using LDAP and then you will have complete access to all the objects.
02-11-2025 08:50 PM
Edit/create the Rule, and then click on the Conditions field to open up the Editor
You can search in the AD Join Points. Under the Dictionary drop-down, look for you AD Join Point name - e.g.
03-10-2025 09:17 PM - edited 03-10-2025 09:45 PM
02-11-2025 07:23 PM
Have you had a look in your AD joined ISE? You can easily check this by navigating to Administration > Identity Management and then clicking on your AD Join Point. Open the 'Attributes' tab and then click 'Add'
Then I tend to select the option 'Select Attributes from directory' and give it a username as an example. I don't know if these extensions should exist in my AD - but I don't see them. Maybe you see them in your ISE.
Failing that, you can also bind ISE to your AD controllers using LDAP and then you will have complete access to all the objects.
02-11-2025 07:40 PM
Okay. How do i then use that attribute as a condition in an authorization policy?
02-11-2025 08:50 PM
Edit/create the Rule, and then click on the Conditions field to open up the Editor
You can search in the AD Join Points. Under the Dictionary drop-down, look for you AD Join Point name - e.g.
03-10-2025 09:17 PM - edited 03-10-2025 09:45 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide