cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

ISE: Auth computer based on AD group

Hi,

I am trying to get ISE to check if a computer is in a specific Active Directory group and then authorize based on that information.

I have connected ISE to Active Directory and successfully added the group domain.com/Users/Domain Computers and then under Authorization I have added the policy IF Any AND domain.com:ExternalGroups EQUALS domain.com/Users/Domain Computers Then PermitAccess.

It is the first rule in the list.

But this doesn't seem to work. The computer goes to the last Default rule. Did I forget to do something?

Regards,

Philip

Who Me Too'd this topic