Cisco Firepower version 6.6 was the last release to support the Cisco Firepower User Agent. After that, only ISE or ISE-PIC was supported to get passive user to IP mappings in MS AD environments.
In current versions of the Secure Firewall Release Notes you can now find the Passive Identity Agent. A reason to be happy! Because the more complex and expensive setups with ISE were not the best choise everywhere.

Resources and more information:
https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/release-notes/threat-defense/760/threat-defense-release-notes-76.html
https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config-76/m_user-control-with-the-passive-identity-agent.html



