01-06-2018 04:27 PM
Hi,
In ISE 2.2, just want to clarify whether the ISE WMI Passive ID provider supports retrieving AD logoff messages directly from the Domain Controllers as part overall logoff detection, or is WMI logoff detection currently only supported through the use of Endpoint Probes and Passive ID session timeouts?
Thanks,
Denis
Solved! Go to Solution.
01-06-2018 08:43 PM
The latter.
01-06-2018 08:43 PM
The latter.
01-07-2018 04:55 PM
Thanks Hsing-Tsu
Are there any plans for ISE to support these messages in future?
01-07-2018 11:33 PM
By default, there are no reliable logoff events generated by endpoints that disconnect from network. This is why we are leveraging direct endpoint probes. If we were able to gather this directly from AD, we would have.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide