Hi
Will these XP machines be domain joined and be using 802.1x? ISE could learn the AD-Operating-System and deny access if this attribute contains "XP"
Alternatively, ISE has an endpoint profile called WindowsXP-Workstation. To become a member of this endpoint group, a device must satisfy at least one of the following conditions:
Type:IP User-Agent CONTAINS Windows NT 5.1
Type:NMAP SMB.operating-system CONTAINS Windows XP
Type:ACTIVEDIRECTORY AD-Operating-System CONTAINS Windows XP
hth
Andy