<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE integration with AD on Azure for Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028962#M453951</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd double-check that, since ISE does not allow Azure AD to be added as an external identity source. Yes, ISE does have SAML integration with Azure AD - but that is quite different than offering MSChapv2 authentication for things like EAP-PEAP authentication. As far as I know, you can not use Azure AD for credential authentication for EAP-PEAP (even if you managed to get a Secure LDAP connection to Azure AD - the password challenge doesn't work over LDAP). You can however use it to perform Authorization (e.g. checking that user X is a member of AD Group).&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 12:44:33 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-02-13T12:44:33Z</dc:date>
    <item>
      <title>ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028049#M453945</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just wanted to confirm if we can use Active Directory on Azure for users authentication with ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 09:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028049#M453945</guid>
      <dc:creator>Karim Bellassoued</dc:creator>
      <dc:date>2020-02-12T09:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028061#M453947</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Yes as a couple of the info's below will confirm :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-integration-with-azure-ad/td-p/3805022" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-integration-with-azure-ad/td-p/3805022&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-integration-with-azure-ad/td-p/3729550" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-integration-with-azure-ad/td-p/3729550&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 09:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028061#M453947</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-02-12T09:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028095#M453949</link>
      <description>&lt;P&gt;Thanks Marce1000 .&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 10:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028095#M453949</guid>
      <dc:creator>Karim Bellassoued</dc:creator>
      <dc:date>2020-02-12T10:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028962#M453951</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd double-check that, since ISE does not allow Azure AD to be added as an external identity source. Yes, ISE does have SAML integration with Azure AD - but that is quite different than offering MSChapv2 authentication for things like EAP-PEAP authentication. As far as I know, you can not use Azure AD for credential authentication for EAP-PEAP (even if you managed to get a Secure LDAP connection to Azure AD - the password challenge doesn't work over LDAP). You can however use it to perform Authorization (e.g. checking that user X is a member of AD Group).&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 12:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4028962#M453951</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-13T12:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4029370#M453952</link>
      <description>&lt;P&gt;Any integration with Azure AD would be done via SAML IdP and ISE does not currently support using a SAML IdP for endpoint authentication. SAML IdP is only supported for authentication of the following portals:&lt;/P&gt;
&lt;UL id="concept_6878301F1F7C460585A4A267ECF77723__ul_fr5_5kh_zdb" class="ul"&gt;
&lt;LI id="concept_6878301F1F7C460585A4A267ECF77723__li_839ADA4C83C1468AAF109B6F7866DC88" class="li"&gt;
&lt;P class="p"&gt;Guest portal (sponsored and self-registered)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="concept_6878301F1F7C460585A4A267ECF77723__li_42F92355DB5E4A50A16D038A9ECEF4D7" class="li"&gt;
&lt;P class="p"&gt;Sponsor portal&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="concept_6878301F1F7C460585A4A267ECF77723__li_E91BD286F67E4ADEA1D0DD57BA31129E" class="li"&gt;
&lt;P class="p"&gt;My Devices portal&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="concept_6878301F1F7C460585A4A267ECF77723__li_2AD664BB37B847D7AFB479EB1A50090A" class="li"&gt;
&lt;P class="p"&gt;Certificate Provisioning portal&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;See the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_01110.html?bookSearch=true#concept_6878301F1F7C460585A4A267ECF77723" target="_self"&gt;ISE Admin Guide&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 21:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4029370#M453952</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-13T21:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4181691#M563737</link>
      <description>&lt;P&gt;Partner SEVT - Security last week updated this guidance, I believe, with arrival of ISE 3.0.&amp;nbsp; Need to confirm tho myself.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 16:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4181691#M563737</guid>
      <dc:creator>netizenden</dc:creator>
      <dc:date>2020-11-10T16:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4309194#M566229</link>
      <description>&lt;P&gt;&lt;SPAN&gt;netizenden, d&lt;/SPAN&gt;id you ever confirm if AD on Azure can be used for EAP authentication with ISE 3.0?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 20:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4309194#M566229</guid>
      <dc:creator>sdcorn</dc:creator>
      <dc:date>2021-03-17T20:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4309343#M566237</link>
      <description>&lt;P&gt;See a similar discussion here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-azure-ad/td-p/4150923" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-access-control/ise-azure-ad/td-p/4150923&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The short answer is that this can only be done directly via ROPC which is very bleeding-edge has its own caveats and limitations.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 01:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4309343#M566237</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-03-18T01:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4960680#M585251</link>
      <description>&lt;P&gt;Hi Greg Gibbs,&lt;/P&gt;
&lt;P&gt;after almost 3 years later, is there any change&amp;nbsp; in SAML IdP for endpoint authentication ?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4960680#M585251</guid>
      <dc:creator>stayd</dc:creator>
      <dc:date>2023-11-16T12:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4961028#M585257</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/253196"&gt;@stayd&lt;/a&gt;... No. SAML is browser-based, so it would require some significant updates to existing EAP protocols or a new EAP protocol to provide this functionality. This is not an ISE limitation, but rather an industry-wide limitation.&lt;/P&gt;
&lt;P&gt;See this blog discussion for current options with ISE and Entra ID.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635" target="_blank" rel="noopener"&gt;Cisco ISE with Microsoft Active Directory, Azure AD, and Intune&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 21:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/4961028#M585257</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-11-16T21:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272238#M595529</link>
      <description>&lt;P&gt;Hi Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does it mean SAML can't not be used for Authorization either?&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/625214"&gt;@Arne&lt;/a&gt;&amp;nbsp;has mentioned in this post: "&lt;SPAN&gt;You can however use it to perform Authorization (e.g. checking that user X is a member of AD Group)."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 22:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272238#M595529</guid>
      <dc:creator>Sdiana</dc:creator>
      <dc:date>2025-03-17T22:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272250#M595530</link>
      <description>&lt;P&gt;No. The currently available options for authentication/authorization of users and devices against Entra ID are in the blog post I previously shared the link for below.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 23:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272250#M595530</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-03-17T23:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272285#M595531</link>
      <description>&lt;P&gt;Thank you, Greg for the reply. Would you also have info about ISE release roadmap? This link&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cs.co/ise-pm" target="_blank" rel="noopener nofollow noreferrer"&gt;cs.co/ise-pm&lt;/A&gt;&amp;nbsp;is Cisco internal. We are deploying ISE 3.3 patch 4 instances in AWS for our customer and want to make sure this release will be Cisco recommended release for at least next 6-7 months.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 02:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272285#M595531</guid>
      <dc:creator>Sdiana</dc:creator>
      <dc:date>2025-03-18T02:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE integration with AD on Azure for Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272723#M595543</link>
      <description>&lt;P&gt;Roadmap is not discussed on public forums. Personally (this is not a commitment from Cisco), I would expect that 3.4 would be designated the recommended release somewhere between 3-6 months from now, but I certainly would not deploy 3.4p1 in production at this time.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 20:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-ad-on-azure-for-authentication/m-p/5272723#M595543</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-03-18T20:57:48Z</dc:date>
    </item>
  </channel>
</rss>

