cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
807
Views
0
Helpful
4
Replies

Filter authorization by end user applications on iOS and Android devices on ISE?

DavidOnTheLeft
Level 1
Level 1

Is there any way to filter out users that don't have a specific app or aren't running a specific service on their phone/tablet when connecting to a network?

4 Replies 4

Stephen Rodriguez
Cisco Employee
Cisco Employee

You need something to profile the devices, which may end up being a mix between MDM and ISE, depending on what all you really are needing to do.

take a look at the specs for ISE, and see what all it can do, and what pieces you can use.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

edondurguti
Level 4
Level 4

As of right now (I am running cisco ise 1.1.1) ISE cannot authorize clients based of what apps they have on their devices, but it can profile them based on type of devices and set them different access, ACL, VLAN etc.

that is where the MDM would come into play.  If they are your users devices, joined to the MDM, you are able to set mandatory and restricted apps.  You can even use the MDM to remove the connection profile if they install a restricted app.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Also ISE 1.2 is coming with API that the mdm devices can you use in order to control devices as they come in to your network. I dont know what those features are but my assumption is that it can blacklist users once the MDM appliance detects that they dont meet your policies.

Thanks,

Tarik Admani
*Please rate helpful posts*

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: