cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2792
Views
10
Helpful
3
Replies

Microsoft Update Posturing

zascherl86
Cisco Employee
Cisco Employee

Is there any way to have ISE tell what patch fails on posturing for windows patching?

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

No, ISE only says if the endpoint is Compliant or Non-compliant with your defined policy.

 

View solution in original post

3 Replies 3

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Here's a bit of a related thread which may contain some hints :

             https://community.cisco.com/t5/network-access-control/ise-posture-failing-for-windows-update-patch/m-p/3989595

 M.



-- ' Listen to the wind, it talks  
          Listen to the silence, it speaks
            Listen to your heart, it knows

So this helps.  Now I've heard 2 different ways it works.

 

1. ISE checks patch release versions against Microsoft to see if up to date.

2. ISE only checks to see if patches are required on the system and not necessarily the patch version.

 

Which one of those would be accurate?

thomas
Cisco Employee
Cisco Employee

No, ISE only says if the endpoint is Compliant or Non-compliant with your defined policy.