nerdexam
Cisco

300-715 · Question #133

When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the…

The correct answer is D. The groups are not added to Cisco ISE under the AD join point. Specific Active Directory groups not appearing in Cisco ISE for authorization policy conditions, while others do, indicates that those groups have not been explicitly added to Cisco ISE under the Active Directory join point.

Policy Enforcement

Question

When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen. What is causing this issue?

Options

  • ACisco ISE only sees the built-in groups, not user created ones
  • BThe groups are present but need to be manually typed as conditions
  • CCisco ISE's connection to the AD join point is failing
  • DThe groups are not added to Cisco ISE under the AD join point

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    7% (4)
  • C
    2% (1)
  • D
    89% (48)

Why each option

Specific Active Directory groups not appearing in Cisco ISE for authorization policy conditions, while others do, indicates that those groups have not been explicitly added to Cisco ISE under the Active Directory join point.

ACisco ISE only sees the built-in groups, not user created ones

Cisco ISE can see and utilize both built-in and user-created Active Directory groups, provided they are configured correctly within the ISE AD identity source.

BThe groups are present but need to be manually typed as conditions

Active Directory groups used in authorization policies must be selectable from a dropdown or search interface in ISE; they cannot be manually typed as conditions because ISE needs to validate their existence and membership.

CCisco ISE's connection to the AD join point is failing

If ISE's connection to the AD join point were failing, no Active Directory groups would be visible or usable, which contradicts the statement that 'other groups that are in the same domain are seen'.

DThe groups are not added to Cisco ISE under the AD join pointCorrect

For Cisco ISE to effectively use Active Directory groups in authorization policies, these groups must be specifically added and synchronized within the Active Directory identity source configuration (the AD join point) in ISE. Even if ISE is joined to the domain and sees other groups, newly created or un-added groups will not appear as selectable attributes in policy conditions until they are explicitly configured in the ISE AD identity source.

Concept tested: Cisco ISE Active Directory group integration

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0101.html#concept_14B157D063A449C0A72B28BBA29A1009

Topics

#Active Directory Integration#Authorization Policies#Group Configuration#Cisco ISE Administration

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice