03-15-2021 07:33 AM
hi y'all.
I have a question , i womder if someone out there can suggest me the easiest way to automatically
kick an authenticated user doing traffic over the network , after i disable his AD account.
Basically if an account has been disabled on AD the user can't join the network , ofcourse.
but if a user is already authenticated inside the network and i disable his account on AD , untill
a re-auth occurs the user keeps been connected and allowed to make traffic inside the network.
So , is there a quick way to re-asses his status on AD trough a keep alive or something that tells ISE to check if the user account is still valid ?
thanks
Solved! Go to Solution.
03-15-2021 03:24 PM
I can only think of two possible ways to accomplish this:
Example AuthZ Profile setting:
03-15-2021 08:14 AM
please try:
in Context Visibility > Endpoints, filter by Username
on Change Authorization > CoA Session Terminate
Hope this helps !!!
03-15-2021 09:25 AM
Thanks for the answer , but as i wrote i would like this to happen automatically as i disable a user inside the AD.
Do you think is that something i can achieve?
thanks again
Eugenio
03-15-2021 03:24 PM
I can only think of two possible ways to accomplish this:
Example AuthZ Profile setting:
03-16-2021 01:43 AM
the REST API looks like a very smart solution ! thanks for the advice !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide