Location in GUI : Work Centers » Network Access » Policy Sets » XXX » Authorization Policy - Local Exceptions
Name Type Constraint Mandatory Default Value authorization_exception_rules List [authorization_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d\_\-\. ]+$ Yes state Choice enabled, disabledNo enabledcondition Class [condition]No profiles List String No security_group String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWith, macContains, macEndsWith, macEquals, macIn, macNotContains, macNotEndsWith, macNotEquals, macNotIn, macNotStartsWith, macStartsWithNo attribute_value String No name String No
Example-1 Network Access Authorization Exception Rule for Wired 802.1X Endpoints by Identity Group
This authorization exception rule provides high-priority network access control for wired 802.1X authenticated devices that belong to a specific endpoint identity group. Authorization exception rules are evaluated before standard authorization rules in the policy evaluation order, making them ideal for scenarios requiring immediate policy decisions that bypass normal rule processing. The rule matches when the IdentityGroup:Name attribute equals “Endpoint Identity Groups:group_1” and applies the PERMIT_vlan1 authorization profile, which likely assigns VLAN 1 access permissions.
authorization_exception_rules :
- name : AUTHZ_DOT1x_wired
type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Endpoint Identity Groups:group_1
Example-2 Network Access Authorization Exception Rule for Quarantining Non-Compliant Devices with Posture Assessment
This authorization exception rule provides immediate quarantine enforcement for devices that fail Cisco ISE posture assessment compliance checks. The rule uses a compound condition (ConditionAndBlock) that matches when BOTH Session:PostureStatus equals “NonCompliant” AND Network Access:AuthenticationMethod equals “MSCHAPV2”, ensuring it captures password-authenticated endpoints that have failed security posture validation.
description : Global policy for network access
service_name : Default Network Access
authorization_exception_rules :
- name : Quarantine_Non_Compliant_Devices
- type : ConditionAttributes
attribute_name : PostureStatus
attribute_value : NonCompliant
- type : ConditionAttributes
dictionary_name : Network Access
attribute_name : AuthenticationMethod
attribute_value : MSCHAPV2
Example-3 Network Access Authorization Exception Rule for Denying Blacklisted and Compromised Endpoints
This authorization exception rule provides immediate and absolute network access denial for endpoints that have been identified as compromised, unauthorized, or otherwise blacklisted by security operations. The rule matches when the IdentityGroup:Name attribute equals “Endpoint Identity Groups:Blacklist” and applies the DenyAccess profile, which completely blocks network connectivity.
description : Global policy for network access
service_name : Default Network Access
authorization_exception_rules :
- name : Blacklist_Compromised_Endpoints
type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Endpoint Identity Groups:Blacklist
Location in GUI : Work Centers » Network Access » Policy Sets » XXX » Authorization Policy - Local Exceptions
Name Type Constraint Mandatory Default Value authorization_exception_rules List [authorization_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabledNo enabledcondition Class [condition]No profiles List String No security_group String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_exception_rules :
- name : AUTHZ_DOT1x_wired
type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Endpoint Identity Groups:group_1
Location in GUI : Work Centers » Network Access » Policy Sets » XXX » Authorization Policy - Local Exceptions
Name Type Constraint Mandatory Default Value authorization_exception_rules List [authorization_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabledNo enabledcondition Class [condition]No profiles List String No security_group String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_exception_rules :
- name : AUTHZ_DOT1x_wired
type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Endpoint Identity Groups:group_1
Location in GUI : Work Centers » Network Access » Policy Sets » XXX » Authorization Policy - Local Exceptions
Name Type Constraint Mandatory Default Value authorization_exception_rules List [authorization_exception_rules]No
Name Type Constraint Mandatory Default Value name String Regex: ^[\w\d_\-\. ]+$ Yes state Choice enabled, disabledNo enabledcondition Class [condition]No profiles List String No security_group String No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo falsedictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributes, ConditionAndBlock, ConditionOrBlockYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No children List [children]No
Name Type Constraint Mandatory Default Value type Choice ConditionReference, ConditionAttributesYes is_negate Boolean true, falseNo dictionary_name String No attribute_name String No operator Choice contains, endsWith, equals, greaterOrEquals, greaterThan, in, ipEquals, ipGreaterThan, ipLessThan, ipNotEquals, lessOrEquals, lessThan, matches, notContains, notEndsWith, notEquals, notIn, notStartsWith, startsWithNo attribute_value String No name String No
authorization_exception_rules :
- name : AUTHZ_DOT1x_wired
type : ConditionAttributes
dictionary_name : IdentityGroup
attribute_value : Endpoint Identity Groups:group_1