01-06-2025 11:07 PM
Hello Everyone
I just wanted to know if Cisco ISE supports Windows 10 IoT Enterprise LTSC for Supplicants (802.1X) and Cisco Secure Client for doing posture.
As per Cisco Identity Services Engine Network Component Compatibility, Release 3.3 mentioned in below link
Cisco Identity Services Engine Network Component Compatibility, Release 3.3 - Cisco
This version is not listed under "Validated Client Machine Operating Systems, Supplicants, and Agents"
But just wanted to confirm if there is roadmap OR what we can do with type of endpoints?
If we just allow based on MAB then it will be risky? Shall I try profiling policy ? But what will happen if this machine is getting connected via VPN
01-07-2025 12:07 AM
as per the doc, it seems to work.. i would suggest just testing for one client and confirm that it works.
From Cisco ISE Release 3.3, Cisco ISE supports unvalidated versions of operating systems in agent-based and agentless posture workflows. In the earlier releases of Cisco ISE, only the endpoints that ran validated operating systems successfully met posture agent policies.
As a result, endpoints running an unvalidated operating system failed posture agent workflows with the error message, The operating system is not supported by the server.
For information on supported operating systems, see the Compatibility Matrix for your Cisco ISE release.
For example, posture agent flows for endpoints running operating system versions Windows 10 IoT Enterprise LTSC or Mac 14 failed while these operating system versions were not validated. When Cisco ISE validated these versions and the operating system data was published to the Feed Service, posture agents successfully matched these endpoints.
You can download the latest operating system data to Cisco ISE from the Feed Service in the Administration > System > Posture > Updates page of the Cisco ISE administration portal.
From Cisco ISE Release 3.3, unvalidated operating systems are matched to a known operating system listed in the Policy pages (Posture, Requirements, and Conditions pages) of the Cisco ISE administration portal, so that posture agent workflows can be completed successfully. For example, if Mac xx is not validated and an endpoint is running it, a posture agent can now match the endpoint with MacOSX. When Mac xx is validated and published to the Feed Service, and the posture agent runs on the endpoint again, the endpoint is matched with Mac xx. Posture reports display the operating system that an endpoint is matched with.
All the posture agents that are supported by Cisco ISE Release 3.3 are impacted by this change. No other Cisco ISE features, such as BYOD, are impacted.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide