nerdexam
Cisco

500-220 · Question #73

Drag and Drop Question Drag and drop the settings from the left onto the available or non-available methods of applying a group policy to a Cisco Meraki MR access point on the right. Answer:

The correct answer is By Sentry Policy; By Radius Attribute; By Device Type; By Client; By VLAN; By Active Directory Group. Cisco Meraki MR Access Point - Group Policy Application Methods The Core Concept The drag-and-drop has two target columns: Available methods and Non-Available methods for applying group policies on a Meraki MR (wireless) access point. The split is: | Available (1–4) |…

Cisco Meraki Wireless Solutions

Question

Drag and Drop Question Drag and drop the settings from the left onto the available or non-available methods of applying a group policy to a Cisco Meraki MR access point on the right. Answer:

Exhibit

500-220 question #73 exhibit

Answer Area

Drag items

By Sentry PolicyBy Radius AttributeBy VLANBy Device TypeBy Active Directory GroupBy Client

Correct arrangement

  • By Sentry Policy
  • By Radius Attribute
  • By Device Type
  • By Client
  • By VLAN
  • By Active Directory Group

Explanation

Cisco Meraki MR Access Point - Group Policy Application Methods

The Core Concept

The drag-and-drop has two target columns: Available methods and Non-Available methods for applying group policies on a Meraki MR (wireless) access point.

The split is:

Available (1–4)Non-Available (5–6)
By Sentry PolicyBy VLAN
By RADIUS AttributeBy Active Directory Group
By Device Type
By Client

Why Each Item Is Placed Here

AVAILABLE Methods

1. By Sentry Policy Meraki Systems Manager (MDM) integrates directly with MR APs via Sentry. When a device enrolls or its compliance state changes, the AP dynamically applies the matching group policy. This is a native Meraki wireless feature.

2. By RADIUS Attribute During 802.1X/WPA-Enterprise authentication, a RADIUS server can return a Meraki VSA (Vendor-Specific Attribute) or Filter-Id attribute naming a group policy. The AP applies it immediately upon authentication. Fully supported on MR.

3. By Device Type Meraki APs perform passive device fingerprinting (user-agent, DHCP options, etc.) to classify clients as iOS, Android, Windows, etc. A matching group policy can be applied automatically. Built into the MR platform.

4. By Client Administrators can manually assign a group policy to a specific client MAC address in the dashboard. This is the most direct, always-supported method on any Meraki device.


NON-AVAILABLE Methods

5. By VLAN VLAN-based group policy assignment is a feature of the MS (switching) platform. On MR APs, VLANs are configured per SSID, not used as a trigger to assign group policies. Applying a policy "by VLAN" is not a supported method in the MR group policy framework.

6. By Active Directory Group While Meraki supports AD integration for splash page authentication, assigning group policies based on AD group membership is not a supported method on MR APs. AD-group-based policy assignment exists on the MS platform or via workarounds (e.g., RADIUS returning the policy name), but not as a direct first-class MR group policy method.


Common Mistakes & Misconceptions

  • VLAN confusion: Candidates often assume VLAN tagging = policy assignment. On MR, VLANs segment traffic per SSID; they don't trigger group policies.
  • AD overestimation: AD integration sounds powerful, so candidates assume it covers group policy assignment on MR. It doesn't - the MR AD integration scope is limited to captive portal/splash authentication.
  • Conflating MS and MR features: Several of the non-available methods work on Meraki switches (MS) but not on wireless APs (MR). Always anchor your answer to the specific platform the question names.

Topics

#group policy#MR access point#wireless policy application#SSID

Community Discussion

No community discussion yet for this question.

Full 500-220 Practice