<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Integration - Azure MFA (Cloud Only Deployment) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4518201#M571632</link>
    <description>&lt;P&gt;Please see our &lt;A href="https://cs.co/ise-guides" target="_self"&gt;ISE Security Ecosystem Integration Guides&lt;/A&gt; &amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231" target="_self" rel="nofollow noopener noreferrer"&gt;How to Deploy ISE Device Admin with Duo MFA&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/duo-mfa-integration-with-ise-for-tacacs-device-administration/ta-p/3881767" target="_self" rel="nofollow noopener noreferrer"&gt;Duo MFA Integration with ISE for TACACS+ Device Administration with Microsoft Active Directory Users&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 21:38:51 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-12-13T21:38:51Z</dc:date>
    <item>
      <title>ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510303#M496205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking into an Azure MFA Cloud deployment and there seems to be some specific NPS server requirements if we want to leverage the solution, at least according to Microsoft.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension"&gt;https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already have an enterprise solution for RADIUS (ISE), scaling out another set of servers/infrastructure for this simple purpose is undesirable. Has anyone deployed this using ISE (not sure that's possible)? Is the PD team working with Microsoft PD to provide a solution using ISE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 16:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510303#M496205</guid>
      <dc:creator>Sloanstar</dc:creator>
      <dc:date>2018-07-12T16:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510304#M496208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please take a look at this post&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/244852"&gt;ISE using Azure MFA and AD&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 22:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510304#M496208</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-07-12T22:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510305#M496210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more post on the same topic.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/287361"&gt;ISE Authentication to Azure MFA - RADIUS PAP Only?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 23:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510305#M496210</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-07-12T23:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510306#M496211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Krish, these cover what Microsoft terms Hybrid MFA deployment requiring an MFA server on premise. For Cloud MFA, that's where the NPS servers come in. Any chance to get the ISE team to talk with Microsoft to see what would be required to get the NPS capability into ISE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 21:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510306#M496211</guid>
      <dc:creator>Sloanstar</dc:creator>
      <dc:date>2018-07-13T21:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510307#M496213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot for your post. I will relay your inquiry to our product management team. Please note that ISE not currently supporting multiple authentications other than EAP chaining and CWA chaining.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2018 16:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510307#M496213</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-14T16:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510308#M496215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This seems more of a RADIUS proxy configuration, but there also seems to be some https calls that are exchanged as well, perhaps for azure account verification? MS would need to fill in the blanks. Thanks for passing it along.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 13:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3510308#M496215</guid>
      <dc:creator>Sloanstar</dc:creator>
      <dc:date>2018-07-16T13:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3908457#M496217</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 04:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/3908457#M496217</guid>
      <dc:creator>mumustha</dc:creator>
      <dc:date>2019-08-15T04:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4027415#M496219</link>
      <description>&lt;P&gt;We leverage Azure MFA for ISE/TACACS authentication.&amp;nbsp; We had it setup in ACS 5.4 and migrated it to ISE.&amp;nbsp; Simple to setup.&amp;nbsp; We verify an network engineer is in the correct AD group and prompt them for second factor before they can log into a CLI for switch/router as well for web gui's on cisco prime and wireless controllers.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 11:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4027415#M496219</guid>
      <dc:creator>usmcjohn</dc:creator>
      <dc:date>2020-02-11T11:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4057260#M559347</link>
      <description>&lt;P&gt;Do you by chance have any documentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to set up Azure MFA with our ISE deployment. We are not seeing any documentation on how to build this out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my understanding today, I feel we will need to deploy Azure MFA cloud base (which seems the only way to have MFA in azure), then we would build a windows server with NPS. The NPS servers would have all my configuration for 2-factor and I would point ISE to the NPS server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything will be of help. We have reached out to MS FastTrack team and it feels they are learning how to deploy this with us.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 01:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4057260#M559347</guid>
      <dc:creator>bmoore821</dc:creator>
      <dc:date>2020-04-02T01:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4492740#M570683</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/269070"&gt;@usmcjohn&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Would you mind sharing any documentation for&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Azure MFA for ISE/TACACS authentication. Pieces of documentation should help too, it no need to be a consolidated one. Hard to find any related documentation in the community so any help from your side would be greatly appreciated.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are thinking between DUO vs AZ MFA.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 14:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4492740#M570683</guid>
      <dc:creator>bhatel</dc:creator>
      <dc:date>2021-10-26T14:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4518201#M571632</link>
      <description>&lt;P&gt;Please see our &lt;A href="https://cs.co/ise-guides" target="_self"&gt;ISE Security Ecosystem Integration Guides&lt;/A&gt; &amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231" target="_self" rel="nofollow noopener noreferrer"&gt;How to Deploy ISE Device Admin with Duo MFA&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/duo-mfa-integration-with-ise-for-tacacs-device-administration/ta-p/3881767" target="_self" rel="nofollow noopener noreferrer"&gt;Duo MFA Integration with ISE for TACACS+ Device Administration with Microsoft Active Directory Users&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 21:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4518201#M571632</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-13T21:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4560539#M573013</link>
      <description>&lt;P&gt;Has anyone checked using this method. I also want to confirm whether below is possible for TACACS+ device administration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE --&amp;gt; NPS Server --&amp;gt; Azure AD for MFA and Active Directory&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 02:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4560539#M573013</guid>
      <dc:creator>AbyLauranceCherian0059</dc:creator>
      <dc:date>2022-02-28T02:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration - Azure MFA (Cloud Only Deployment)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4805046#M580856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you elaborate more on your setup. Are you using NPS with Azure MFA extension? if so are you able to get the OTP (one-time password) to work? MS will enforce number matching by May of 2023 and the Accept/Deny push notification will stop working. Only number matching and OPT will be allowed. I was able to get ISE to work with NPS + Azure MFA extension with push notification but it stops working when I switch to OTP. On my case I can see the NPS sending a challenge with the code but ISE ignores it and keeps sending access requests&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE_NPS.jpg" style="width: 898px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/180566iCBF289FEC9645F43/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE_NPS.jpg" alt="ISE_NPS.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 21:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-azure-mfa-cloud-only-deployment/m-p/4805046#M580856</guid>
      <dc:creator>Aomar bahloul</dc:creator>
      <dc:date>2023-03-30T21:31:33Z</dc:date>
    </item>
  </channel>
</rss>

