cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1396
Views
5
Helpful
1
Replies

MDM Lookup to gain attributes only?

Josh Morris
Level 3
Level 3

I am trying to gain access to more attributes such as MacOS version since Apple may stop putting the version number in the User Agent field. I have JAMF as an MDM and already use it to validate compliance for VPN clients. I'm wondering if anyone has used an MDM lookup strictly as a means to gain more attributes for a device. I know reaching out to MDM for authZ can add additional connectivity time, so I'm not really wanting to do that. But is there another way for me to reach out to the MDM to check a device?

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

The MDM API is mainly intended to validate Registration/Compliance status of the endpoint from the MDM/DDM and is only triggered by an AuthZ Policy that uses those attributes.

The ideal mechanism for external systems to share endpoint contextual data with ISE would be via pxGrid, but JAMF would need to develop a pxGrid publisher mechamism that ISE could then consume as a subscriber.

View solution in original post

1 Reply 1

Greg Gibbs
Cisco Employee
Cisco Employee

The MDM API is mainly intended to validate Registration/Compliance status of the endpoint from the MDM/DDM and is only triggered by an AuthZ Policy that uses those attributes.

The ideal mechanism for external systems to share endpoint contextual data with ISE would be via pxGrid, but JAMF would need to develop a pxGrid publisher mechamism that ISE could then consume as a subscriber.