When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen.
What is causing this issue?
- Cisco ISE’s connection to the AD join point is failing.
- Cisco ISE only sees the built-in groups, not user created ones.
- The groups are not added to Cisco ISE under the AD join point.
- The groups are present but need to be manually typed as conditions.
Answer(s): C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/ b_ISE_AD_integration_2x.html
Reveal Solution Next Question