01-05-2018 12:51 AM
Hi,
Testing ISE 2.3P1 BYOD flow using NSP. Certificate successfully installed and Windows 7 does not seem to be able to use the certificate for authentication.
With the same endpoint the certificate authentication work before joining domain.
Any specified privilege needed?
Wing Churn
01-05-2018 09:07 AM
Please check whether any GPO from the domain is controlling the configuration for the native supplicant. This process requires local admin privileges and the certificate might be installed under a different user, if one used in the UAC prompt.
01-07-2018 11:05 PM
Hi,
Do you by any chance have a document handy for AD requirement? I am hacing issue on another use case which require NSP to download AnyConnect.
Wing Churn
01-08-2018 11:25 AM
There is no requirement for AD. ISE BYOD would work with endpoints not joined to the AD, but it does need the user in the local admin group of the client device.
An AD administrator may use GPO to enforce the Windows supplicant behavior, however, as shown in [ISE Lab Guide] ISE Active Directory Integration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide