cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3155
Views
0
Helpful
4
Replies

ISE 2.3 Active Directory OU authentication

Hi,

I'm trying to create a  authorization policy using an active directory OU (both user and machine objects).  But I'm unable to the OU to ISE.  It only allow security groups. Please advise.

2 Accepted Solutions

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

It's not recommended to use OU, which is not indexed, so would result in poorer performance.

If you have to use it, then you may write conditions on the AD attribute "distinguishedName"

View solution in original post

Join ISE to Active Directory.  Then add whatever groups you want to use into ISE.  At that point, then you will be able to use the AD groups in your authorization policies.

View solution in original post

4 Replies 4

hslai
Cisco Employee
Cisco Employee

It's not recommended to use OU, which is not indexed, so would result in poorer performance.

If you have to use it, then you may write conditions on the AD attribute "distinguishedName"

kenneth-goh
Beginner
Beginner

How do I create Authorization Policy using Active Directory Security Groups? Thanks.

Join ISE to Active Directory.  Then add whatever groups you want to use into ISE.  At that point, then you will be able to use the AD groups in your authorization policies.

I could see the option for OU 'CERTIFICATE Subject - Organization Unit'

Which option is for Active Directory Security Policy to add the groups? 

CERTIFICATE Subject - Organization Unit.PNG

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: