cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1619
Views
0
Helpful
4
Replies

Pre-login posture assessment - possible with ISE?

Phillip Macey
Level 1
Level 1

Does anyone know if it is possible (or not) to have a windows machine posture assessed on boot? ie. before anyone logs in on it. Currently, I have to log in on my machine before the assessment starts. It would be good to have assessment begin as soon as the machine boots so that (assuming the machine passes assessment) it is completed by the time I log in. We are using the NAC Agent with ISE1.2.

 

Thanks in advance for your thoughts.

 

 

2 Accepted Solutions

Accepted Solutions

As far as i know, the posture agent does not do anything before user has logged in, i have never seen a posture report in ise, that indicates anything else, because you would get many failed posture compliance checks, if it did (checking user keys, user files, av status and so on in machine land).

View solution in original post

nspasov
Cisco Employee
Cisco Employee

It is not possible. The Windows Logon process and similar functions happen before the NAC/Posture agent starts/loads up. 

 

Thank you for rating helpful posts!

View solution in original post

4 Replies 4

jan.nielsen
Level 7
Level 7

What things where you thinking you could check when the machine is booting ?

Stuff that is not (I assume) dependent on the user logging in. eg. AV is installed (and running?), some registry keys.
 

As far as i know, the posture agent does not do anything before user has logged in, i have never seen a posture report in ise, that indicates anything else, because you would get many failed posture compliance checks, if it did (checking user keys, user files, av status and so on in machine land).

nspasov
Cisco Employee
Cisco Employee

It is not possible. The Windows Logon process and similar functions happen before the NAC/Posture agent starts/loads up. 

 

Thank you for rating helpful posts!