Three Reasons a Name Shows Up in an Enforcement Report
Anomaly lists get read as accusations. Most of the time the network is behaving exactly as somebody configured it to.
Enforcement anomaly reports have a tone problem. They present a list of user accounts under a heading that sounds like a verdict, and they are read by people who have the authority to act on one.
In practice, three ordinary situations put a row there, and none of them is misconduct.
A device was exempted on purpose. Printers, cameras, building management controllers and lab equipment often sit behind a MAC exception because they cannot do 802.1X. The exception is documented somewhere, usually not where the person reading the report is looking.
A session outlived its record. Someone authenticated, the session was long, and the lease or the accounting record rolled over in between. The traffic is legitimate and the paperwork simply does not line up.
A segment was never in scope. A VLAN gets added during a building project, enforcement is scheduled for phase two, and phase two slips. The report has no way to know that.
So our version of this table ends with a sentence saying exactly that: treat these as candidates, not verdicts, and here are the three conditions that produce one. It costs a line of text. It has, we think, saved a few people from an uncomfortable conversation they did not deserve.
The general rule we now apply: if a screen can be read as an accusation against a person, it does not ship without the sentence that bounds it.
nac
operations