
Network access control: who gets in, from where, on which VLAN — the microsegmentation that starts at the socket.
ISE decides who enters the network and what they can do: it authenticates users and devices (802.1X, MAB), profiles them (is that MAC a printer or a laptop?), puts them in the right VLAN/SGT and — with software-defined segmentation — enforces who talks to whom. The socket in the meeting room stops being an open door onto the heart of the company.


Monitor mode first, enforcement later: the network controlled without blocking the company on Monday.
Sponsor portals and onboarding: the guest browses, but only where they should.
Printers, cameras and sensors in their own bubble: the weak device is no longer the bridge.
ISE + industrial networks: OT inside access control too, with judgment.
ISE decides who enters the network and with what rights: 802.1X for the managed, MAB and profiling for the IoT, the posture checks verify the endpoint (patches, AV) before access, the results (authorizations, TrustSec SGTs) segment by identity instead of by VLAN; the guest portal handles guests and BYOD; pxGrid shares context with firewalls and XDR: quarantine becomes automatic (ANC).
Who was on the network, when, from where: the answer ready.
Employees, consultants and machines on the same infrastructure, separated.
Duo's complement: identity on the access, ISE on the network.