I meant from ISE. What's the Username collected from ISE? sAMAccountName or UserPrincipalName?
PDP needs something to make ldap query for group membership resolution.
Error message from Smartlog in your post may point to the issue that the wrong one is used.
In case the Attr received leads to errors when trying to resolve group memberships, sometimes UserLoginAttr is to be modified in the Checkpoint Database using guidbedit.
In case pdp process queries using wrong attr, user cannot be found, leading to same error message as above.
To clarify, you might want to debug.
Then first enable debug on the PDP
fw debug fwd off PDP_LOG_SIZE=50000000
fw debug fwd off PDP_NUM_LOGS=20
fw kill pdpd
pdp debug off
pdp debug reset
pdp debug set all all
replicate issue
disable debug
fw debug fwd off PDP_LOG_SIZE=10000000
fw debug fwd off PDP_NUM_LOGS=10
pdp debug off
pdp debug reset
fw kill pdpd
and then you are able to analyse the collected files in $FWDIR/logs/pdpd.elg*
In case my idea is correct, you could see hints pointing to that.
Or maybe pointing to a different root cause.
and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite