<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can cisco ise integrate with windows server ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083960#M560296</link>
    <description>&lt;P&gt;Perhaps you can share the link that you are referring to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A q&lt;A href="https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-plan-access-from-anywhere" target="_self"&gt;uick google search reveals that there is an RD Gateway&lt;/A&gt; that allows remote users to access the RDP services and this is coupled with a second factor authentication. That's where the RADIUS integration comes in. I don't fully understand it myself - but it seems that the MFA setup makes a RADIUS request to the RADIUS server (NPS/ISE whatever) and the RADIUS server has to authenticate the MFA request. If successful, then the MFA sends the SMS or notification to the user's mobile device. I don't believe it requires any specific ISE functionality.&amp;nbsp; &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg" target="_self"&gt;Microsoft have documented all the gory details here&lt;/A&gt; and they mention their own NPS server in the document - but I reckon ISE could also do the job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2020 10:26:29 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-05-12T10:26:29Z</dc:date>
    <item>
      <title>how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083834#M560285</link>
      <description>&lt;P&gt;how can cisco ise integrate with windows server for windows login and use 2 factor authen via cisco ise ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 06:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083834#M560285</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2020-05-12T06:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083860#M560286</link>
      <description>Update&lt;BR /&gt;how can Remote desktop authentication with Cisco ISE ?</description>
      <pubDate>Tue, 12 May 2020 07:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083860#M560286</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2020-05-12T07:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083889#M560287</link>
      <description>&lt;P&gt;Let's turn that question around and ask, does Windows Server have any reason to use RADIUS for anything? I don't believe it has a RADIUS interface for any kind of authentication. If it does, then any RADIUS server can be used.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 08:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083889#M560287</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-05-12T08:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083898#M560290</link>
      <description>&lt;P&gt;Thank you for answer .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found some post about Remote desktop authentication via cisco ise but I confused about this function .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you explain for more detail ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 08:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083898#M560290</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2020-05-12T08:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083960#M560296</link>
      <description>&lt;P&gt;Perhaps you can share the link that you are referring to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A q&lt;A href="https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-plan-access-from-anywhere" target="_self"&gt;uick google search reveals that there is an RD Gateway&lt;/A&gt; that allows remote users to access the RDP services and this is coupled with a second factor authentication. That's where the RADIUS integration comes in. I don't fully understand it myself - but it seems that the MFA setup makes a RADIUS request to the RADIUS server (NPS/ISE whatever) and the RADIUS server has to authenticate the MFA request. If successful, then the MFA sends the SMS or notification to the user's mobile device. I don't believe it requires any specific ISE functionality.&amp;nbsp; &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg" target="_self"&gt;Microsoft have documented all the gory details here&lt;/A&gt; and they mention their own NPS server in the document - but I reckon ISE could also do the job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 10:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4083960#M560296</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-05-12T10:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4084466#M560332</link>
      <description>&lt;P&gt;I don't understand the exact scenario you are asking about since you were not detailed in your question.&lt;/P&gt;
&lt;P&gt;1) Can ISE integrate with Windows Server: This is a general AD integration question. Yes, it if is an Active Directory domain controller, ISE can join the domain to use AD as an Identity Store/server for authenticating users.&lt;/P&gt;
&lt;P&gt;2) Can cisco ise integrate with windows server for windows login: This sounds like a user login/network access control question using 802.1X and RADIUS. ISE will only authenticate domain computer or domain servers if 802.1X is enabled. This is extremely rare for servers since they are usually remotely managed and Windows RDP doesn't generate an 802.1X Login event.&lt;/P&gt;
&lt;P&gt;3) Windows login and use 2 factor authen via cisco ise:&amp;nbsp; ISE can authenticate a user doing a Windows login using 802.1X against Windows Active Directory if you configure the Windows wired supplicant (Wired AutoConfig Service). However 2 factor authentication with 802.1X is not currently possible.&lt;/P&gt;
&lt;P&gt;4) use 2 factor authen via cisco ise: if 2 factor is the most important thing, you may use 2 factor authentication using a Self-Registered Guest web portal in ISE with a SAML Identity Provider that offers 2FA/MFA.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 21:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4084466#M560332</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-05-12T21:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: how can cisco ise integrate with windows server ?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4085691#M560422</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your information .&amp;nbsp; I already update to the customer . I recommend they . They can choose Cisco DUO or Google Authenticator etc .. I think it's the best way for this solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 11:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-cisco-ise-integrate-with-windows-server/m-p/4085691#M560422</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2020-05-14T11:13:51Z</dc:date>
    </item>
  </channel>
</rss>

