cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
594
Views
10
Helpful
2
Replies

ISE best practice for computer authentication question

BrianPersaud
Spotlight
Spotlight

Hi All

I am in the process of deploying ISE at a company.  The question is focused on wired authentication for AD joined computers.

Is there a benefit of doing authorization using certificates vs ISE checking if the computer is in a particular AD group e.g. Domain computers?

I am on ISE 2.4 Patch 9

 

Thanks

 

Brian

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Some benefits of cert-based auth are

  • AD replications on password changes could be slow
  • Password authentication might not be allowed; e.g. Microsoft Windows Defender Credential Guard

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

Some benefits of cert-based auth are

  • AD replications on password changes could be slow
  • Password authentication might not be allowed; e.g. Microsoft Windows Defender Credential Guard

Damien Miller
VIP Alumni
VIP Alumni
You can still check group membership or AD attributes of machines when doing certificate authentication. It is common to leverage one or the other to provide differentiated access while doing machine certificate auth.

Taking it a step further you could also leverage AnyConnect NAM with eap-chaining, authenticating both the machine and user at the same time.

It really comes down to the unique requirements of the deployment, no one is the same and there are many valid methods.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: