Any reason why you have the same network access on pending and compliant? Do you pre-deploy CSC/Anyconnect or do you use the provisioning portal? If the endpoint is in a pending state, wouldn’t you want to only allow access to ISE for client provisio...
Hello @Marcelo Morais I am still a bit confused on this. Here are my current settings:TEAP with EAP-TLS, we have separate authorization policies for machine (no posturing) and user authentication (yes posturing)Default compliant state is set to Non-C...