cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
868
Views
0
Helpful
3
Replies

ISE BYOD NSP with AD domain user

wileong
Cisco Employee
Cisco Employee

Hi,

Testing ISE 2.3P1 BYOD flow using NSP. Certificate successfully installed and Windows 7 does not seem to be able to use the certificate for authentication.

With the same endpoint the certificate authentication work before joining domain.

Any specified privilege needed?

Wing Churn

3 Replies 3

hslai
Cisco Employee
Cisco Employee

Please check whether any GPO from the domain is controlling the configuration for the native supplicant. This process requires local admin privileges and the certificate might be installed under a different user, if one used in the UAC prompt.

wileong
Cisco Employee
Cisco Employee

Hi,

Do you by any chance have a document handy for AD requirement? I am hacing issue on another use case which require NSP to download AnyConnect.

Wing Churn

hslai
Cisco Employee
Cisco Employee

There is no requirement for AD. ISE BYOD would work with endpoints not joined to the AD, but it does need the user in the local admin group of the client device.

An AD administrator may use GPO to enforce the Windows supplicant behavior, however, as shown in [ISE Lab Guide] ISE Active Directory Integration.