
Cisco ISE Training
Master Cisco Identity Services Engine and take full control of network access in enterprise environments. This training covers everything from 802.1X policy sets and TACACS+ administration to TrustSec segmentation and BYOD onboarding. Build the practical skills employers need for secure, scalable network deployments.
What you will learn:
This course covers the complete Cisco ISE platform, starting with NAC fundamentals and ISE architecture and moving through identity source integration, policy set design, and authorization rule configuration. You will configure guest portals, posture compliance workflows, and BYOD onboarding processes. The training also addresses TrustSec security group tagging, pxGrid ecosystem integration, and REST API automation. Monitoring dashboards, advanced troubleshooting tools, and high-availability deployment design are included. By the end, you will have the technical depth to plan, deploy, and operate ISE in a production enterprise network.
How you study in practice Cisco ISE Training
How you practise Cisco ISE Training
For companies looking to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.
Course content
8 Chapters • 35 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Cisco ISE and NAC
Introduction to Cisco ISE and NAC
Lesson 1 • ISE Installation and Initial Setup
Walks through hardware and virtual appliance installation, initial CLI configuration, and GUI access. Prepares students to operate a functional ISE lab environment.
Lesson 2 • Cisco ISE Architecture Overview
Introduces ISE personas, nodes, and deployment models. Connects component roles to the NAC concepts introduced in the previous section.
Lesson 3 • ISE Dashboard and Navigation
Orients students to the ISE admin portal, dashboards, and menu structure. Efficient navigation is prerequisite to all subsequent configuration tasks.
Lesson 4 • Network Access Control Fundamentals
Covers the purpose of NAC, policy enforcement points, and authentication frameworks. Establishes the security problem ISE solves before introducing the product.
Chapter 2HideHide detailsSee detailsIdentity Sources and Directory Integration
Identity Sources and Directory Integration
Lesson 1 • Active Directory Integration
Configures ISE join points, machine and user authentication, and AD group retrieval. AD is the most common enterprise identity source for ISE deployments.
Lesson 2 • Certificate-Based Authentication
Configures ISE as a certificate authority and sets up EAP-TLS authentication. Certificates are essential for machine and BYOD authentication scenarios.
Lesson 3 • Internal Identity Database
Covers ISE's built-in user and endpoint identity stores. Provides a baseline before introducing external directory dependencies.
Lesson 4 • Identity Source Sequences and Fallback
Defines ordered identity source sequences and fallback behaviour for failed lookups. Ensures resilient authentication when primary sources are unavailable.
Lesson 5 • LDAP and External Identity Sources
Extends identity integration to LDAP directories and ODBC databases. Broadens authentication options beyond Microsoft environments.
Chapter 3HideHide detailsSee detailsPolicy Sets and Authorization Rules
Policy Sets and Authorization Rules
Lesson 1 • Policy Set Architecture
Explains the three-tier policy model: policy sets, authentication rules, and authorization rules. Understanding this hierarchy is required for all policy configuration tasks.
Lesson 2 • Wired and Wireless Policy Scenarios
Applies policy sets to real wired 802.1X and wireless WPA2-Enterprise scenarios. Bridges abstract policy concepts to practical network deployments.
Lesson 3 • Policy Troubleshooting and Optimisation
Uses ISE diagnostic tools to identify and fix policy mismatches and authentication failures. Optimisation techniques reduce rule complexity and improve evaluation speed.
Lesson 4 • Authorization Profiles and Results
Creates authorization profiles that return VLAN, dACL, SGT, and URL-redirect results. Profiles define what access a matched endpoint or user receives.
Lesson 5 • Conditions and Dictionaries
Builds conditions using ISE dictionaries, attributes, and compound expressions. Conditions are the building blocks of every authentication and authorization rule.
Chapter 4HideHide detailsSee detailsNetwork Device Administration and TACACS+
Network Device Administration and TACACS+
Lesson 1 • TACACS+ Authentication and Authorization
Builds device admin policy sets with shell profiles and command sets. Enforces least-privilege access for network engineers and operators.
Lesson 2 • Network Device Groups and Profiles
Organises managed devices into groups and creates device profiles for vendor-specific attributes. Grouping enables scalable, role-based policy application.
Lesson 3 • TACACS+ Protocol and ISE Device Admin
Contrasts TACACS+ with RADIUS and explains ISE's device administration persona. Establishes protocol fundamentals before configuration begins.
Lesson 4 • Accounting and Audit Trails
Configures TACACS+ accounting to log all commands executed on network devices. Audit logs satisfy compliance requirements for privileged access management.
Chapter 5HideHide detailsSee detailsProfiling and Endpoint Visibility
Profiling and Endpoint Visibility
Lesson 1 • Endpoint Identity Groups and Policy
Maps profiled endpoints to identity groups and applies differentiated authorization policies. Connects profiling output to actionable access control decisions.
Lesson 2 • Built-In and Custom Endpoint Profiles
Reviews Cisco-supplied profiling policies and creates custom profiles for proprietary devices. Custom profiles extend ISE classification to non-standard endpoints.
Lesson 3 • Profiling Architecture and Probes
Explains how ISE collects endpoint attributes via probes and feeds them to the profiling engine. Probe selection directly affects classification accuracy.
Lesson 4 • Context Visibility and Endpoint Analytics
Uses the ISE context visibility workspace and endpoint analytics to monitor device inventory. Provides operational insight into all connected endpoints in real time.
Chapter 6HideHide detailsSee detailsGuest Access and Web Authentication
Guest Access and Web Authentication
Lesson 1 • Central Web Authentication Flow
Implements CWA redirect using ISE authorization profiles and WLC or switch integration. CWA is the most common web authentication method for guest and BYOD.
Lesson 2 • Guest Reporting and Compliance
Generates guest access reports and configures acceptable-use policy enforcement. Reporting supports audit requirements for visitor network access.
Lesson 3 • Guest Access Design and Portals
Introduces guest access use cases and the ISE portal framework. Portal type selection determines the guest onboarding workflow and security posture.
Lesson 4 • Sponsor Portal and Guest Management
Configures sponsor groups, approval workflows, and guest account lifecycle management. Sponsors control guest access without requiring ISE admin privileges.
Chapter 7HideHide detailsSee detailsPosture Assessment and Compliance
Posture Assessment and Compliance
Lesson 1 • Posture Conditions and Requirements
Creates posture conditions for OS patches, antivirus, firewall, and file checks. Conditions combine into requirements that define a compliant endpoint state.
Lesson 2 • Posture Architecture and Agents
Explains the posture assessment flow, agent types, and ISE posture service components. Agent selection determines what compliance checks are available.
Lesson 3 • Remediation and Reporting
Configures automatic remediation actions and generates compliance reports for auditors. Remediation reduces helpdesk burden by guiding users to self-correct.
Lesson 4 • Posture Policy and Enforcement
Builds posture policies that map requirements to operating systems and user groups. Enforcement uses authorization profiles to restrict non-compliant endpoints.
Chapter 8HideHide detailsSee detailsTrustSec, SGT, and Advanced Segmentation
TrustSec, SGT, and Advanced Segmentation
Lesson 1 • TrustSec Architecture and SGT Concepts
Introduces TrustSec components, SGT assignment methods, and the security group matrix. Understanding the architecture is required before configuring any TrustSec policy.
Lesson 2 • SXP and Non-TrustSec Device Support
Deploys SXP to propagate IP-to-SGT mappings to devices that lack inline tagging support. SXP extends TrustSec policy to legacy infrastructure.
Lesson 3 • TrustSec Monitoring and Troubleshooting
Uses ISE reports and network device commands to verify and debug TrustSec policy. Monitoring ensures segmentation policy is enforced as designed.
Lesson 4 • SGT Assignment in ISE
Configures static and dynamic SGT assignment via authorization profiles and profiling. Accurate assignment is the foundation of effective segmentation policy.
Lesson 5 • Security Group ACLs and Enforcement
Creates SGACLs and maps them to the security group matrix for east-west traffic control. SGACLs replace traditional ACLs with identity-aware enforcement.
Your valid completion certificate
This course is for you:
Network Administrator: ready to move beyond basic access control configurations.
Security Engineer: responsible for enforcing identity-based policies across enterprise infrastructure.
Systems Integrator: deploying Cisco solutions that require ISE as a core component.
IT Professional pursuing CCNP Security or related Cisco certification credentials.
Help Desk Technician: advancing towards a network security or infrastructure engineering role.
Compliance Officer: needing technical fluency to evaluate and audit NAC deployments.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in Nigeria?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















