cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1019
Views
0
Helpful
2
Replies

ISE authorization policies with only one AD group

drivera_
Level 1
Level 1

Hello, everybody

 

I would like to ask you something. Is there any way for configuring authorization profiles on ISE with differents permissions by having only one AD group? We have a customer that only has an AD group and he wants users to be assigned on a VLAN by the ISE depending on the user role, I mean, users must be serapated by VLANs as a final authorization permission on Authorization profiles, so the customer wants every user has a VLAN depending on the user role. I don't know how to tell ISE to assign a VLAN depending on a role that is not defined on AD. I hope you guys have understood me.


Thank you in advance.

1 Accepted Solution

Accepted Solutions

You ISE need a differentiation in the context to separate the endpoints into different authorisation profiles. If the differentiation is not known anywhere in the ISE, then you can't do that. You have to tell your customer to put all employees into a corresponding windows-group or rethink the requirement.

View solution in original post

2 Replies 2

You ISE need a differentiation in the context to separate the endpoints into different authorisation profiles. If the differentiation is not known anywhere in the ISE, then you can't do that. You have to tell your customer to put all employees into a corresponding windows-group or rethink the requirement.

Hi Karsten,

 

Thank you for your reply.  I'm gonna tell our customer that it is necessary rethink the requirement.