300-715 · Question #133
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the…
The correct answer is D. The groups are not added to Cisco ISE under the AD join point. Specific Active Directory groups not appearing in Cisco ISE for authorization policy conditions, while others do, indicates that those groups have not been explicitly added to Cisco ISE under the Active Directory join point.
Question
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen. What is causing this issue?
Options
- ACisco ISE only sees the built-in groups, not user created ones
- BThe groups are present but need to be manually typed as conditions
- CCisco ISE's connection to the AD join point is failing
- DThe groups are not added to Cisco ISE under the AD join point
How the community answered
(54 responses)- A2% (1)
- B7% (4)
- C2% (1)
- D89% (48)
Why each option
Specific Active Directory groups not appearing in Cisco ISE for authorization policy conditions, while others do, indicates that those groups have not been explicitly added to Cisco ISE under the Active Directory join point.
Cisco ISE can see and utilize both built-in and user-created Active Directory groups, provided they are configured correctly within the ISE AD identity source.
Active Directory groups used in authorization policies must be selectable from a dropdown or search interface in ISE; they cannot be manually typed as conditions because ISE needs to validate their existence and membership.
If ISE's connection to the AD join point were failing, no Active Directory groups would be visible or usable, which contradicts the statement that 'other groups that are in the same domain are seen'.
For Cisco ISE to effectively use Active Directory groups in authorization policies, these groups must be specifically added and synchronized within the Active Directory identity source configuration (the AD join point) in ISE. Even if ISE is joined to the domain and sees other groups, newly created or un-added groups will not appear as selectable attributes in policy conditions until they are explicitly configured in the ISE AD identity source.
Concept tested: Cisco ISE Active Directory group integration
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0101.html#concept_14B157D063A449C0A72B28BBA29A1009
Topics
Community Discussion
No community discussion yet for this question.