cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
945
Views
0
Helpful
4
Replies

What is the best practice to check if MacOS device is Domain Joined or not?

Nate Zhang
Cisco Employee
Cisco Employee

In one of the deployment, we need to check MacOS is Domain Joined or not so that we can apply ISE posture check to that device.

If this is a Non-Domain Joined device (like BYOD) device, we would apply it to go through BYOD flow.

Authentication is using EAP-PEAP.

1 Accepted Solution

Accepted Solutions

You can use the AD attribute - "AD-Host-Exists = True" as a condition.

 

View solution in original post

4 Replies 4

Francesco Molino
VIP Alumni
VIP Alumni
Hi

If mac devices are joined to a Microsoft AD domain, it means the object ad will be a member, at least of domain computers.

If you create a rule that use this group, the result will show if the device is member or not of your AD.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi Francesco,

Thank you for the information. Yes, the Mac devices are Domain Joined.
Could you elaborate more about the rule? How should it be configured and which condition to be used?

You can use the AD attribute - "AD-Host-Exists = True" as a condition.

 

Sorry for my late answer I was at Cisco Live but you got the answer. Sorry

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: