07-08-2021 12:39 AM
Dear community,
Is there a way to distinguish RDP access form from direct access on Windows supplicants from ISE? This in order to be able to apply different rules for both use Cases.
Any though would be highly appreciated. .
Thank you,
Laura
Solved! Go to Solution.
07-08-2021 07:24 AM
Microsoft does not treat RDP logins as normal user logins and therefore does not trigger an 802.1X authentication event for an RDP login. The switch or wireless controller should not receive an EAP-Start message from a Windows workstation when you login via RDP.
You may consider using the Cisco AnyConnect NAM module which provides the functionality you desire.
Here is another article stating the same:
https://www.ise-support.com/2019/02/05/windows-rdp-and-802-1x-authentications/
07-08-2021 07:24 AM
Microsoft does not treat RDP logins as normal user logins and therefore does not trigger an 802.1X authentication event for an RDP login. The switch or wireless controller should not receive an EAP-Start message from a Windows workstation when you login via RDP.
You may consider using the Cisco AnyConnect NAM module which provides the functionality you desire.
Here is another article stating the same:
https://www.ise-support.com/2019/02/05/windows-rdp-and-802-1x-authentications/
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide