Concept and mechanism
Network access combines identification, authentication, posture, and enforcement. MAB accommodates devices without 802.1X, but a MAC address does not provide the same cryptographic proof as a certificate. Profiling identifies device characteristics; it does not alone demonstrate current patches or active protection. In EAP-TLS, server trust must remain valid after CA renewal. Fix chain, identity, and distribution instead of disabling validation. When policy changes for an active session, CoA depends on NAD capabilities and appropriate attributes. A central console can show the desired decision without the access point having applied it.
Guided application
In a fictional handover, ISE indicates compliant while the NAD returns NAK and the session stays restricted. Keep validation open, investigate rejection, and confirm effective state, using controlled reauthentication where the procedure provides it. In Duo, a setting configured in an application-group policy can take precedence over global policy; inspect context and effective policy. Integration-supported FIDO2/WebAuthn passkeys provide phishing-resistance properties that cannot be attributed to every mechanism merely called MFA. Plan account recovery. Finally, an allowed HTTPS channel can carry misuse. Correlate activity and authorization; for high-impact automatic response, scope targets, enrich evidence, and use approval according to the playbook. API existence does not grant authorization for every possible action.
Compliant in the console and NAK at the NAD mean session validation remains outstanding.
Common pitfalls
Profile as posture; MAB as certificate; decision as enforcement; MFA as uniform guarantee; API as authorization.
Related topics: Risk, identity, and AI security · Encryption, VPNs, and APIs · Firewall, inspection, and layer-two protection
Close the decision only with evidence of effective state.
Reference: Secure access and NAD profiles · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security