cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
880
Views
0
Helpful
3
Replies

WMI Passive Authentication Logoff Detection

dvan
Cisco Employee
Cisco Employee

Hi,

In ISE 2.2, just want to clarify whether the ISE WMI Passive ID provider supports retrieving AD logoff messages directly from the Domain Controllers as part overall logoff detection, or is WMI logoff detection currently only supported through the use of Endpoint Probes and Passive ID session timeouts?

Thanks,

Denis

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee
3 Replies 3

hslai
Cisco Employee
Cisco Employee

The latter.

dvan
Cisco Employee
Cisco Employee

Thanks Hsing-Tsu

Are there any plans for ISE to support these messages in future?

By default, there are no reliable logoff events generated by endpoints that disconnect from network.  This is why we are leveraging direct endpoint probes.  If we were able to gather this directly from AD, we would have.