<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Azure AD ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4181056#M563720</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have gone through that link but could not find ISE Configuration Guide its is only Azure Configuration Guide. Can you help me what ISE configuration required in 3.0 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;PP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 18:03:57 GMT</pubDate>
    <dc:creator>pattani.parag23</dc:creator>
    <dc:date>2020-11-09T18:03:57Z</dc:date>
    <item>
      <title>ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4150923#M562828</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Folks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We’ve got a customer who is adopting Azure AD and has operations in several countries.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Their use case includes 802.1X for wired/wireless, VPN and Guest services.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As far as i know, we currently support Azure AD with SAML, which could take care of the Guest Services and VPN part of the request (&lt;A href="https://community.cisco.com/t5/security-documents/notes-on-azure-ad-as-saml-idp/ta-p/3644255" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/notes-on-azure-ad-as-saml-idp/ta-p/3644255&lt;/A&gt;).&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; However, for 802.1X wired/wireless services, it is my understanding that we officially do not support it yet (&lt;A href="https://community.cisco.com/t5/network-access-control/ise-integration-with-azure-ad/td-p/3805022" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-access-control/ise-integration-with-azure-ad/td-p/3805022&lt;/A&gt;).&amp;nbsp; I’ve seen some notes on the possibility about using LDAPS, but this approach has limitations (ie: PEAP-MSCHAP-v2).&amp;nbsp; Other folks advise to join MS AD directly.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It is my understanding that ISE on Public Cloud is on the roadmap as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please, any advise, experiences, ideas, official take on on this or roadmap information is more than welcome.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;.:|:.:|:.&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Cristian Venegas&amp;nbsp;&lt;/STRONG&gt;|&amp;nbsp; Technical Solutions Architect - Security&amp;nbsp;|&amp;nbsp;+56 (9) 9632 1494 |&amp;nbsp;&lt;A href="mailto:crvenega@cisco.com" target="_blank" rel="noopener"&gt;crvenega@cisco.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 19:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4150923#M562828</guid>
      <dc:creator>Cristian Venegas</dc:creator>
      <dc:date>2020-09-14T19:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4151041#M562835</link>
      <description>&lt;P&gt;The only current method of directly integrating ISE &amp;amp; Azure AD is via SAML, which is limited to specific Portal-based authentication. There currently no industry-standard method for authenticating 802.1x via SAML/OAuth except maybe &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth-ropc" target="_blank" rel="noopener"&gt;ROPC&lt;/A&gt; which is really just a stop-gap and not recommended for use in Production at this time.&lt;/P&gt;
&lt;P&gt;Roadmap is not discussed on this public forum. For roadmap info, reach out to the ISE PMs on &lt;A href="https://cs.co/ise-pm" target="_blank" rel="noopener"&gt;cs.co/ise-pm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 02:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4151041#M562835</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-09-15T02:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4173765#M563523</link>
      <description>&lt;P&gt;ISE 3.0 supports 802.1X with Azure AD using ROPC.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/release_notes/b_ise_30_rn.html#concept_uhf_4rm_gnb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/release_notes/b_ise_30_rn.html#concept_uhf_4rm_gnb&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 15:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4173765#M563523</guid>
      <dc:creator>surasky</dc:creator>
      <dc:date>2020-10-26T15:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4179926#M563665</link>
      <description>&lt;P&gt;Hi Surasky&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning to Implement - &amp;gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;( 802.1X + MAB ) For Wired and Wireless&amp;nbsp;Corporate user on ISE 3.0 with Azure AD using ROPC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are lookin here Implementation guide. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Requesting to you please share.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 12:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4179926#M563665</guid>
      <dc:creator>pattani.parag23</dc:creator>
      <dc:date>2020-11-06T12:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4180099#M563670</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There is only limited 802.1X Support, and ROPC is only supported using EAP-TTLS with PAP as the inner method (Clear Text). This means support for somewhat unsecure username/password, it's in clear text but it is encapsulated in the EAP-TTLS outer tunnel. There is no support for Certificates yet.&lt;/P&gt;&lt;P&gt;For now i would recommend looking into doing a combination of 802.1X and MDM Integration instead of ROPC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 17:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4180099#M563670</guid>
      <dc:creator>Nicolai Borchorst</dc:creator>
      <dc:date>2020-11-06T17:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4181056#M563720</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have gone through that link but could not find ISE Configuration Guide its is only Azure Configuration Guide. Can you help me what ISE configuration required in 3.0 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;PP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 18:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4181056#M563720</guid>
      <dc:creator>pattani.parag23</dc:creator>
      <dc:date>2020-11-09T18:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4977261#M585704</link>
      <description>&lt;P&gt;Has something changed in the last 3 years? is&amp;nbsp; ROPC still not recommended for production?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 15:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4977261#M585704</guid>
      <dc:creator>bergamok</dc:creator>
      <dc:date>2023-12-13T15:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Azure AD ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4977491#M585714</link>
      <description>&lt;P&gt;ROPC still has significant performance limitations (max 50 authentications per second) and user experience issues. See this blog for available options related to Entra ID.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 21:01:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-azure-ad/m-p/4977491#M585714</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-12-13T21:01:35Z</dc:date>
    </item>
  </channel>
</rss>

