<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Admin Login 2FA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3699245#M507905</link>
    <description>&lt;P&gt;Yes, this should work.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0101.html#ID766" target="_blank"&gt;Administrative Access to Cisco ISE Using an External Identity Store&lt;/A&gt;&amp;nbsp;says,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID766__li_31B828D68C3A46EE9E1FA90BA19E691C" class="li"&gt;
&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="link ulchildlink"&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0101.html#ID929" target="_blank"&gt;Configure Admin Access Using an External Identity Store for Authentication with Internal Authorization&lt;/A&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As DUO is a RADIUS token ID source similar to RSA SecurID, we would follow the same mode and need creating internal admin users with the same usernames as those on DUO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 01 Sep 2018 22:44:14 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-09-01T22:44:14Z</dc:date>
    <item>
      <title>ISE Admin Login 2FA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3697112#M507895</link>
      <description>&lt;P&gt;Can you enable DUO auth within a policy for ISE admin login on the landing ISE page?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 15:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3697112#M507895</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2018-08-29T15:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Admin Login 2FA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3697230#M507898</link>
      <description>&lt;P&gt;Please do Search the community for existing answers before posting questions.&lt;/P&gt;
&lt;DIV class="lia-page-header"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/two-factor-authentication-on-ise-2fa-on-ise/ta-p/3636120" target="_self"&gt;Two Factor Authentication on ISE – 2FA on ISE&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/using-duo-with-ise-2-3-and-acs-5-x-for-2fa-cisco-network-admin/ta-p/3642171" target="_self"&gt;Using DUO with ISE 2.3 and ACS 5.X for 2FA Cisco Network Admin Access&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 29 Aug 2018 17:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3697230#M507898</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2018-08-29T17:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Admin Login 2FA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3699245#M507905</link>
      <description>&lt;P&gt;Yes, this should work.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0101.html#ID766" target="_blank"&gt;Administrative Access to Cisco ISE Using an External Identity Store&lt;/A&gt;&amp;nbsp;says,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID766__li_31B828D68C3A46EE9E1FA90BA19E691C" class="li"&gt;
&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="link ulchildlink"&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0101.html#ID929" target="_blank"&gt;Configure Admin Access Using an External Identity Store for Authentication with Internal Authorization&lt;/A&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As DUO is a RADIUS token ID source similar to RSA SecurID, we would follow the same mode and need creating internal admin users with the same usernames as those on DUO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 22:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3699245#M507905</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-01T22:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Admin Login 2FA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3876233#M507907</link>
      <description>Very unhelpful answer given that both of the links address something different than what he asked for.&lt;BR /&gt;</description>
      <pubDate>Wed, 19 Jun 2019 17:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3876233#M507907</guid>
      <dc:creator>Christopher Bell</dc:creator>
      <dc:date>2019-06-19T17:48:43Z</dc:date>
    </item>
  </channel>
</rss>

