Why your NAC deployment is still in monitor mode
Most network access control deployments never reach enforcement. The reason is organisational, not technical — and it is fixable.
- Cisco ISE
- 802.1X
- enforcement
There is a particular kind of security control that costs six figures, renews annually, and blocks nothing. Network access control is the most common example. The deployment goes in, it gets switched to monitor mode so nobody’s laptop stops working during rollout, and then it stays there. For years.
If that describes your environment, the useful thing to understand is that this is the normal outcome, not an unusual failure. It happens to competent teams with good products. Knowing why makes it straightforward to fix.
Monitor mode is not a safety setting
Monitor mode — Cisco calls it Monitor Mode, other vendors call it audit or passive mode — runs your access policy against real traffic and reports what it would have denied, while authorising everything. It exists so you can find out what enforcement would break before it breaks it.
That is genuinely valuable, and it is a stage. The problem is that it is also extremely comfortable. Nothing is broken. The dashboards look busy. The control appears to be working to anyone who does not look closely. There is no forcing function that makes anyone move to the next step, and there is a very obvious personal risk to whoever does.
The three things that keep it there
Nobody owns the exception list. Monitor mode produces a list of things that would have been denied. Some are genuinely unauthorised. Most are printers, badge readers, cameras, lab equipment, or a contractor’s laptop. Each one needs a decision, and each decision needs someone willing to make it. Without an owner and a deadline, the list grows until it is too large to work through, at which point it becomes evidence that enforcement is impossible.
The rollback is theoretical. Teams are asked to enforce with no tested way back. That is a reasonable thing to refuse. A rollback that has never been executed is not a rollback, it is an intention — and the first time you find out whether it works should not be during an outage at 9am.
The help desk has not been told. Enforcement changes what users experience when something goes wrong. If the first the help desk hears about it is the call volume, the change gets reversed within the hour, and the organisation learns that enforcement causes outages.
Notice that none of these are technical problems. This is why buying a different product almost never fixes it.
What moving forward actually looks like
Time-box the monitor period and define its exit condition. “We will run monitor mode for six weeks, and we will exit when the would-have-denied list is fully triaged” is a plan. “We are in monitor mode” is a state.
Triage the exception list by device class, not device. Two thousand denials are usually twelve device classes. Decide once per class — this class authenticates by certificate, this class is profiled and posture-checked, this class gets a dedicated segment with restricted reachability — and the individual count stops mattering.
Test the rollback before you need it. Execute it in a controlled window on a real stage. The point is not just that it works, it is that the team has done it once and knows how long it takes.
Enforce by stages with defined success criteria. One site, one floor, one device class. Nothing goes wide until a bounded group has run enforced through a normal business day — including the Monday morning when everyone reconnects at once.
Brief the help desk with a runbook. What users will see, which failures are expected during the change, what to do about each. If the help desk can resolve the first-day calls without escalating, the rollout survives its first contact with reality.
The part worth saying plainly
Most stalled deployments have sound infrastructure. The switching is configured, the appliances are healthy, the integration works. What stalled was the policy and change-management work — which is a much smaller problem than “our NAC project failed” suggests, and a much cheaper one to finish than to start again.
Before anyone proposes replacing what you own, it is worth establishing what it can already do.