12-17-2012 09:37 AM - edited 03-10-2019 07:54 PM
Good afternoon,
How would ISE deal with an user that has multiple entries for "memberOf"for group assignment? Would ISE use the 1st MemberOf value it encounter to assign a group?
Thanks.
Cath.
Solved! Go to Solution.
12-18-2012 04:48 PM
Yes, that was a typo on my end You want generic towards the bottom and specific towards the top. Think of it that way: Everyone is part of "domain users" so everyone would match that rule but not everyone would be a member of the "executives" so you would want the executives group to be above the domain users
12-17-2012 08:08 PM
Hello Cath-
ISE will "read" the groups in the order that you have configured them in your authorization rules. So I would recommend that you place the more specific groups towards the bottom and the most common groups towards the bottom. For example:
IF member of executives then authorization profile executives_users
IF member of domain users then authorization profile regular_users
Thank you for rating!
12-18-2012 04:02 AM
Thanks Neno.
Could you please clarify your suggestion "...I would recommend that you place the more specific groups towards the bottom and the most common groups towards the bottom".
You mean placing the specific at the top and the generic at the bottom, right?
Thank you.
Cath.
12-18-2012 04:48 PM
Yes, that was a typo on my end You want generic towards the bottom and specific towards the top. Think of it that way: Everyone is part of "domain users" so everyone would match that rule but not everyone would be a member of the "executives" so you would want the executives group to be above the domain users
12-19-2012 04:38 AM
Thank you Neno for all your help.
Regards,
cath.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide