cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3640
Views
0
Helpful
4
Replies

ISE 2.3 Active Directory OU authentication

Hi,

I'm trying to create a  authorization policy using an active directory OU (both user and machine objects).  But I'm unable to the OU to ISE.  It only allow security groups. Please advise.

2 Accepted Solutions

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

It's not recommended to use OU, which is not indexed, so would result in poorer performance.

If you have to use it, then you may write conditions on the AD attribute "distinguishedName"

View solution in original post

Join ISE to Active Directory.  Then add whatever groups you want to use into ISE.  At that point, then you will be able to use the AD groups in your authorization policies.

View solution in original post

4 Replies 4

hslai
Cisco Employee
Cisco Employee

It's not recommended to use OU, which is not indexed, so would result in poorer performance.

If you have to use it, then you may write conditions on the AD attribute "distinguishedName"

kenneth-goh
Level 1
Level 1

How do I create Authorization Policy using Active Directory Security Groups? Thanks.

Join ISE to Active Directory.  Then add whatever groups you want to use into ISE.  At that point, then you will be able to use the AD groups in your authorization policies.

I could see the option for OU 'CERTIFICATE Subject - Organization Unit'

Which option is for Active Directory Security Policy to add the groups? 

CERTIFICATE Subject - Organization Unit.PNG