<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating On-Prem Cisco WSA S395 with Microsoft Entra ID in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5349768#M11596</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;You can’t directly integrate an on-prem Cisco WSA S395 with Microsoft Entra ID for authentication because WSA doesn’t support Entra ID as a native identity provider. Instead, you typically use one of these workarounds:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Sync on-prem AD to Entra ID (via Entra Connect) and keep WSA pointed at on-prem AD/LDAP or Kerberos/NTLM for user auth.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Use Cisco ISE or another identity proxy that can consume Entra ID signals and pass group/user info to WSA.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;For cloud-based identity-aware web filtering, consider Cisco Secure Web Appliance with Umbrella or move to Umbrella SIG, which integrates natively with Entra ID.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In short: No direct Entra ID auth on WSA—use AD/ISE, or move to a cloud solution that supports Entra ID.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 25 Nov 2025 10:23:03 GMT</pubDate>
    <dc:creator>jameswood32</dc:creator>
    <dc:date>2025-11-25T10:23:03Z</dc:date>
    <item>
      <title>Integrating On-Prem Cisco WSA S395 with Microsoft Entra ID</title>
      <link>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5349763#M11595</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I would like to integrate our on-prem WSA S395 with Entra ID to manage admin logins both on the GUI and via CLI. Unfortunately, I can only find documentation online for the ESA, which refers to the menu item &lt;STRONG&gt;“System Administration &amp;gt; SAML”&lt;/STRONG&gt;, but this option does not exist on the WSA.&lt;/P&gt;&lt;P&gt;Can anyone tell me if this is even possible or where I can find documentation for it?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 09:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5349763#M11595</guid>
      <dc:creator>Jens.Wall1</dc:creator>
      <dc:date>2025-11-25T09:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating On-Prem Cisco WSA S395 with Microsoft Entra ID</title>
      <link>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5349768#M11596</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;You can’t directly integrate an on-prem Cisco WSA S395 with Microsoft Entra ID for authentication because WSA doesn’t support Entra ID as a native identity provider. Instead, you typically use one of these workarounds:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Sync on-prem AD to Entra ID (via Entra Connect) and keep WSA pointed at on-prem AD/LDAP or Kerberos/NTLM for user auth.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Use Cisco ISE or another identity proxy that can consume Entra ID signals and pass group/user info to WSA.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;For cloud-based identity-aware web filtering, consider Cisco Secure Web Appliance with Umbrella or move to Umbrella SIG, which integrates natively with Entra ID.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In short: No direct Entra ID auth on WSA—use AD/ISE, or move to a cloud solution that supports Entra ID.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 25 Nov 2025 10:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5349768#M11596</guid>
      <dc:creator>jameswood32</dc:creator>
      <dc:date>2025-11-25T10:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating On-Prem Cisco WSA S395 with Microsoft Entra ID</title>
      <link>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5350051#M11597</link>
      <description>&lt;P&gt;what is the code running on WSA ?&lt;/P&gt;
&lt;P&gt;check enhancement :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwk69930" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCwk69930&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;other option if you have ISE :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-web-appliance-virtual/221634-configure-swa-second-factor-authenticati.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-web-appliance-virtual/221634-configure-swa-second-factor-authenticati.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 07:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/integrating-on-prem-cisco-wsa-s395-with-microsoft-entra-id/m-p/5350051#M11597</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-26T07:40:30Z</dc:date>
    </item>
  </channel>
</rss>

