cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1139
Views
0
Helpful
2
Replies

ISE Passive Identity

stamperbrian
Level 1
Level 1

Trying to get this setup and it appears to be successful when I setup the DC's and configure them.  This is for FMC in the background to identify users/devices.  However, in the dashboard the provider always shows down.  After a lot of research it appears due to a number of Microsoft changes the DC's no longer allow this WMI connectivity.  I found a number of posts regarding un-installing a patch or putting in a reg key to fix it but it appears that was sunset as well in early/mid 2022.  I attempted to deploy the agents as well and those appear to have been successful but it still doesn't appear to work.  

Whole goal here is to let FMC/FTD be able to identify users from AD.  Works just fine if the user actually authenticated to ISE (dot1x, etc) but if the user is just an AD user logging into a machine and that machine simply logs into the domain and never authenticates to ISE, the mapping in ISE never happens and thus FMC/FTD never learns anything about the device.

Is there anyway to get this working now?  I've used the downloadable user agent in the past but according to documentation its being EOL'd too.  

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Don't use the WMI-based Passive ID Agent, use the newer EVT-based agent.

Configure EVT-Based Identity Services Engine Passive ID Agent 

View solution in original post

2 Replies 2

Charlie Moreton
Cisco Employee
Cisco Employee

Don't use the WMI-based Passive ID Agent, use the newer EVT-based agent.

Configure EVT-Based Identity Services Engine Passive ID Agent 

This was it.  I had already deployed the agents but hadn't added the DCs using the agents!  Story of my life.  One step short of my goal   Thank you so much!