ISE 3.2 Multi-MDM Authorization Notes
ISE 3.2 Multi-MDM Authorization Notes
Requirement: if specific group/location users are being managed by specific MDM server, then you
can define policies in ISE to get compliance info and give access accordingly. In below snapshot, I
was making use of AD groups to differentiate MDM users managed by MDM server.
Problems: If there is no differentiation of users/devices being managed by MDM server, then how do
you write policies? Or If an un-enrolled device comes into network and the device/user doesn’t belong
to any of the groups/location, then to which MDM server ISE has to query with?
ISE will first query against MobileIron and falls back to Intune policy to query against multiple MDM
vendors.