cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
220
Views
0
Helpful
1
Replies

ISE And local Machine Access

Hellow guys,

I created policies for Machine and user authentication under ISE, so if the machine and user is AD authenticated, then Authorization profile will be applied.

My question, if the Machine AD authenticated but the user is using local account to access, i want this user to have specific access, not deny.

How can i acheive this?

Regards

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not exactly what you asked for but this might work:

Copy the first AuthC result (machine and user is from AD identity source) to a second one without the user check. Since the AuthC results are evaluated top down with first match ending the processing, the second one will only be checked where there is a machine authentication but no user authentication (at least not on any identity store that ISE know about).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: