Which Authorization Profile Option Supports MSE Room-Based Wireless Access?
An engineer is deploying Cisco ISE into an existing wireless environment for a hospital. The requirement from the customer is that the WLC use Cisco ISE for Central Web Authentication. The company also has a Cisco MSE that is used with the WLC to restrict access to patient records over wireless to the room of the patient only. Which option must be selected in the Authorization Profile on Cisco ISE to support the integration?
Community Votes
75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can separate an ISE policy condition (MAP Location, taken from the MSE) from an Authorization Profile attribute (Track Movement) — the trap is choosing MAP Location because it is the attribute that visibly grants per-room access.
In Cisco ISE, per-room wireless authorization for a hospital using a Cisco MSE requires the Track Movement check box inside the Authorization Profile, while MAP Location is only evaluated as an authorization policy condition. This page explains why the answer to the profile-level question is Track Movement (C) rather than MAP Location.
Most learners choose MAP Location (A) because it is the attribute that actually restricts access to the patient's room, but MAP Location belongs in the authorization policy rule from the MSE integration, not in the Authorization Profile the question explicitly asks about.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Track Movement is the only one of the four options that is a selectable check box inside the Cisco ISE Authorization Profile, which is exactly what the question asks for. When it is checked, ISE registers the endpoint for location tracking with the integrated Cisco MSE and queries that MSE roughly every five minutes to see whether the endpoint has changed location. If the patient device roams into a different room, the change in location triggers a CoA and the endpoint is re-authorized against the MAP Location condition so the correct room-scoped profile is reapplied. Without Track Movement enabled in the profile, ISE never re-polls the MSE, so a device could keep access to the previous room's records after moving. Because the requirement is specifically MSE-driven room restriction on a WLC using Central Web Authentication, the profile-level switch that makes the location data actionable is Track Movement.Why the Other Options Are Wrong
MAP Location (A) is a real and necessary piece of the overall solution, but it is consumed in the authorization policy rule as a condition (matched against the MSE-reported map/location attribute), not selected in the Authorization Profile — the question asks for a profile setting, so A is the classic near-miss. Access Type (B) is a valid Authorization Profile element (for example setting ACCESS_ACCEPT), but it has nothing to do with MSE location or CoA on roaming. Service Template (D) is not the ISE Authorization Profile mechanism used to bind MSE location data to a session; service/device-administration style concepts do not perform location tracking. Only Track Movement changes ISE's runtime behaviour toward the MSE, which is the integration the scenario requires.Community Comment Notes
One commenter, Cachaman, draws the line cleanly, noting that MAP Location is chosen in the authorization policy whereas "For the Authorization profile you check Track Movement" and linking Cisco's location-based authorization with Mobility Services Engine documentation. ce1997d makes the same distinction, observing that both pieces are needed for the solution to work but that the profile check box is the one being asked about, so "the correct answer is Track Movement." AliAhmed reinforces the mechanics, explaining that checking Track Movement makes ISE query the relevant MSE for endpoint location every five minutes to verify whether the location changed. Only dawlims argues for MAP Location, correctly stating that the MSE MAP Location attribute grants access based on location, but that describes where the condition lives in the policy rather than what is configured in the Authorization Profile.Official Reference
Exam Strategy
On ISE questions, first decide whether the stem is asking about a policy condition, an authorization policy rule, or an Authorization Profile attribute — the same word (location in this case) can appear in all three places. MAP Location is matched as a condition, while Track Movement is the profile switch that keeps that location current via MSE polling and CoA.
Frequently Asked Questions
Why is MAP Location not the answer if it restricts access per patient room?
MAP Location is evaluated as a condition in the authorization policy rule using data from the MSE integration. It cannot be selected inside the Authorization Profile, which is what this question asks about.
What does enabling Track Movement in the ISE Authorization Profile actually do?
ISE queries the integrated MSE for the endpoint's location about every five minutes and triggers a CoA when the location changes, re-applying the room-scoped authorization profile.