Ah. Yes. If you want that delay and to count on the MDM being updated.
OnGuard will monitor the machine continuously and report changes near immediately while the client device is connected. Different solution for a different need. Also provides the functionality regardless of whether or not an MDM is able to be used, for instance in a BYOD environment.
------------------------------
Carson Hulcher, ACEX#110
------------------------------
Original Message:
Sent: Dec 08, 2025 05:44 PM
From: ahollifield
Subject: Onguard license usage and cppm port requirements
I am not. You can have the authentication to back through the Service Policies to be re-evaluated once the re-auth timer expires. At that point the MDM can be queried for updated status.
Original Message:
Sent: 12/8/2025 5:35:00 PM
From: chulcher
Subject: RE: Onguard license usage and cppm port requirements
I think you might be confusing OnGuard with Onboard?
The 802.1X reauth timer has nothing to do with the posture evaluation timer/timeout.
------------------------------
Carson Hulcher, ACEX#110
------------------------------
Original Message:
Sent: Dec 08, 2025 05:29 PM
From: ahollifield
Subject: Onguard license usage and cppm port requirements
Not true on the at time of connection. OnGuard when requires connectivity to the ClearPass server for posture eval. MDM can use only the certificate GUID or MAC address, which are available without granting any access.
You can set your reauth timer on the 802.1X to be whatever value you want to re-evaluate posture. But yes agree it's not 100% continuous.
Original Message:
Sent: 12/8/2025 5:05:00 PM
From: chulcher
Subject: RE: Onguard license usage and cppm port requirements
OnGuard can provide posture assessment at the time of network connection, along with validating that posture requirement constantly. MDM isn't as useful for those requirements.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Dec 08, 2025 12:16 PM
From: ahollifield
Subject: Onguard license usage and cppm port requirements
Also why not use an MDM integration or Extension integration for this instead? Avoids the extra OnGuard license, management and install of the client, etc.