cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
656
Views
5
Helpful
1
Replies

ISE Intune Dynamic VLAN segmentation

kaveh7199
Level 1
Level 1

Hi All

 

Based on the following : https://www.youtube.com/watch?v=iAKyIHFqbgE&t=3067s&ab_channel=CiscoISE-IdentityServicesEngine :

Is it possible we do "Dynamic VLAN assigment" for WIndows 10 devices Managed by Intune (Hybrid Joined) ? example : HR ppl login to onpremies wired LAN and get assigned to VLAN 10 only . similarly do segmentation based on Azure AD groups

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Sure, Dynamic VLAN assignment can be configured in the Authorization Profile.  Though, I'd encourage you to read this thread describing the issues with dynamic VLAN assignment:  https://community.cisco.com/t5/network-access-control/endpoints-getting-ip-from-switchport-vlan-before-ise-changes/td-p/4779903

Segmentation based on Azure AD Groups can be done using ISE 3.2 and EAP-TLS.

View solution in original post

1 Reply 1

Charlie Moreton
Cisco Employee
Cisco Employee

Sure, Dynamic VLAN assignment can be configured in the Authorization Profile.  Though, I'd encourage you to read this thread describing the issues with dynamic VLAN assignment:  https://community.cisco.com/t5/network-access-control/endpoints-getting-ip-from-switchport-vlan-before-ise-changes/td-p/4779903

Segmentation based on Azure AD Groups can be done using ISE 3.2 and EAP-TLS.