ā08-17-2023 01:28 AM
Hello Community
I am working 802.1x authentication using ISE. On the external identity sources I have been able to add/retrieve the domain computers group from AD but I do not see the retrieved group when trying to add it in the authorization policy condition. I only see groups that my current user account is a member of in AD. what could be reason for this.
thanks
ā08-17-2023 03:54 AM
I've seen this before where the AD groups take some time to show up in the conditions studio. Log out / login back in to ISE. Also try a different browser. What version of ISE is this?
ā08-17-2023 04:26 AM
Its been days now. I am able see users groups but unable to see computer groups retrieved from AD
It's version 3.1
ā08-17-2023 06:38 AM
Can ISE retrieve groups for a given machine account using the "Test User" feature?
The is available on the "Connection" tab of the Active Directory External Identity Source:
Set Authentication Type to Lookup and enter machine name in Username box.
hth
Andy
ā08-17-2023 10:47 AM
Make sure you click Save after selecting the groups. The should be available immediately.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide