<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk cloud with MFA through Cisco ISE in Integrated Security Platform</title>
    <link>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4666408#M792</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;So I have a bit of an interesting idea that I'm trying to accomplish. I currently have Splunk Cloud setup with an LDAP bind to my Azure AD setup and it works just fine. I also have a on-prem ISE setup that will force MFA for things like VPN and so forth through radius. What I'm trying to do is point splunk to my on-prem ISE setup and have it BIND with my ISE setup to see if I can't force MFA that way. The trouble that I'm running into is Binding splunk to ISE which I'm not sure if that is even possible. I'm sure there is a way of doing this through possible proxies or Network policy servers, but I'd like to use what I have and not have to resort to other applications like Duo and so forth. I know that path would work, but I'd like to try and use the path I already have setup. It might not even be possible, but I'm sure there is a way &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The end goal here is to get Splunk (or other apps) to force MFA through ISE. Any thoughts?&lt;/P&gt;&lt;P&gt;Path:&lt;/P&gt;&lt;P&gt;user login --&amp;gt; Splunk (cloud)&amp;nbsp; ---&amp;gt; ISE (on-prem) --&amp;gt; ISE to Azure (NPS proxy that prompts MFA) --&amp;gt; user logs in&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Aug 2022 12:25:33 GMT</pubDate>
    <dc:creator>John Mink</dc:creator>
    <dc:date>2022-08-09T12:25:33Z</dc:date>
    <item>
      <title>Splunk cloud with MFA through Cisco ISE</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4666408#M792</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;So I have a bit of an interesting idea that I'm trying to accomplish. I currently have Splunk Cloud setup with an LDAP bind to my Azure AD setup and it works just fine. I also have a on-prem ISE setup that will force MFA for things like VPN and so forth through radius. What I'm trying to do is point splunk to my on-prem ISE setup and have it BIND with my ISE setup to see if I can't force MFA that way. The trouble that I'm running into is Binding splunk to ISE which I'm not sure if that is even possible. I'm sure there is a way of doing this through possible proxies or Network policy servers, but I'd like to use what I have and not have to resort to other applications like Duo and so forth. I know that path would work, but I'd like to try and use the path I already have setup. It might not even be possible, but I'm sure there is a way &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The end goal here is to get Splunk (or other apps) to force MFA through ISE. Any thoughts?&lt;/P&gt;&lt;P&gt;Path:&lt;/P&gt;&lt;P&gt;user login --&amp;gt; Splunk (cloud)&amp;nbsp; ---&amp;gt; ISE (on-prem) --&amp;gt; ISE to Azure (NPS proxy that prompts MFA) --&amp;gt; user logs in&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 12:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4666408#M792</guid>
      <dc:creator>John Mink</dc:creator>
      <dc:date>2022-08-09T12:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cloud with MFA through Cisco ISE</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4697926#M803</link>
      <description>&lt;P&gt;Hello John,&lt;/P&gt;
&lt;P&gt;For deploying Splunk-for-ISE Add-on &amp;amp; Cisco Identity Service Engine (ISE) please refer below link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/identity-services-engine-and-splunk-apps-configuration-guide/ta-p/3735814" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/identity-services-engine-and-splunk-apps-configuration-guide/ta-p/3735814&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow word-break-ie11"&gt;You can also learn more about ISE through our live Ask the Experts (ATXs) session. Check out Cisco Endpoint Security ATXs Resources [&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-endpoint-security-ask-the-experts-resources/ta-p/4394492" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-endpoint-security-ask-the-experts-resources/ta-p/4394492&lt;/A&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;If this doesn't help please email me, I would like to setup a Webex to discuss your issues.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ujjawal&lt;/P&gt;
&lt;P&gt;urathod@cisco.com&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 07:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4697926#M803</guid>
      <dc:creator>urathod</dc:creator>
      <dc:date>2022-10-04T07:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cloud with MFA through Cisco ISE</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4735766#M821</link>
      <description>&lt;P&gt;Cisco ISE serves RADIUS requests. Splunk Cloud will not send RADIUS requests to your on-prem ISE.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 15:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/splunk-cloud-with-mfa-through-cisco-ise/m-p/4735766#M821</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2022-12-09T15:20:31Z</dc:date>
    </item>
  </channel>
</rss>

