cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
702
Views
0
Helpful
2
Replies

ISE Identity Groups in AuthZ Policy

Ben Meagher
Level 1
Level 1

So we all know we can leverage identity groups in authorization policy, can we leverage two of them ? I tried building a compound condition that uses an identity group (MAB) along with another identity group (User) and can not get the policy to hit..Thoughts?

2 Replies 2

jj27
Spotlight
Spotlight

Hi Ben,

Have you tried modifying the AuthZ policy directly and under the conditions section, choose an Endpoint Identity Group as well as a User Identity Group?  I was able to do this in ISE 1.2.

 

 

jan.nielsen
Level 7
Level 7

I doubt that, as far as i can tell with ISE, when you are being authenticated either by mab or by a user/pass with ex PEAP, your identity is established as either, not both, and the identity is what gets compared to identity groups.