08-30-2021 08:39 AM
Hi Guys
i have subject in 2.1 latest patch cube. aaatest'er gets successfully authenticated against internal identities store only. but within AuthZ-policy it unexpectedly queries AD which shouldnt ever happen from my pov. or did i miss something?
08-30-2021 02:56 PM
You need to show us your Authorization Policy - if there is reference to an AD Group lookup, then of course it will query AD.
08-30-2021 08:45 PM
hi Arne
AuthZ policy is in the top of screenshot in the end of my initial msg. It refers to internaluser.name &device type only
08-30-2021 11:41 PM
Oh yes of course - pre-ISE 2.3 - forgotten how that looked. You're right - there should not have been any AD involved.
Are you sure that you hit that "Switch AAA Test" and not something else (before, or after that Policy?)
08-30-2021 11:47 PM
Hi Arne
absolutely sure. u can see from screenshot "15004 Matched rule - Switch AAA test " & there r no others similar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide