<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AnyConnect - M365 authentication possibilities in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4610998#M574821</link>
    <description>&lt;P&gt;AnyConnect NAM client 802.1X authentication to ISE?&amp;nbsp; AnyConnect VPN to ASA/FTD?&amp;nbsp; AzureAD/ADFS?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2022 16:04:15 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2022-05-16T16:04:15Z</dc:date>
    <item>
      <title>Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4610975#M574820</link>
      <description>&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="8793d5ff0a0a3c08548b83ca00e3bc1a" aria-hidden="false" aria-labelledby="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN class="section " data-header-only="false"&gt;&lt;SPAN&gt;Would like to request information on the integration possibilities of AnyConnect with Microsoft 365 user authentication.&lt;BR /&gt;&lt;BR /&gt;So far it looks like it is possible via SAML, just want to make sure we're not missing anything.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 15:28:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4610975#M574820</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-05-16T15:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4610998#M574821</link>
      <description>&lt;P&gt;AnyConnect NAM client 802.1X authentication to ISE?&amp;nbsp; AnyConnect VPN to ASA/FTD?&amp;nbsp; AzureAD/ADFS?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 16:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4610998#M574821</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-16T16:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4611746#M574832</link>
      <description>&lt;P&gt;The AnyConnect VPN client can authenticate to Azure AD via SAML. You can also incorporate Microsoft Authenticator MFA in this scenario.&lt;/P&gt;
&lt;P&gt;You can also run a hybrid solution using Microsoft NPS on premises with the Azure plug-in and use Microsoft MFA that way.&lt;/P&gt;
&lt;P&gt;Thirdly you could use Duo SSO integrated with Azure AD.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 15:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4611746#M574832</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-05-17T15:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4612183#M574836</link>
      <description>&lt;P&gt;I'm also just learning about the M365/AzureAD (AAD) capabilities, but hopefully, we will find something together.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our PoC environment, we have proven that AnyConnect with the external browser could authenticate straight away against AAD using SAML, but this is where the next challenge comes: if at all possible, we would like to use a single sign-on experience on the AzureAD joined devices, namely we would like skip the re-authentication (username+password) of the user and just prompt for multi-factor authentication before the user would be allowed to bring up the VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco provides the AnyConnect app in AzureAD, I wonder if there is any associated documentation on the topic, particularly on the SSO side.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 08:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4612183#M574836</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-05-18T08:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4612569#M574856</link>
      <description>&lt;P&gt;Form memory, when you configure the SAML iDP from FMC there is an option to check the box to not require reauthentication. HAve you tried that?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 18:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4612569#M574856</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-05-18T18:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4613735#M574897</link>
      <description>&lt;P&gt;From SAML authentication's perspective Azure AD is an Identity Provider (IdP), just like ADFS, DUO, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we want to do is the best possible integration between AnyConnect and Azure AD, where the user can establish the VPN connection with the least amount of interactions, still with the best security.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're trying to achieve that AnyConnect authenticates the user based on the Windows session against AzureAD (so there's no new username and password requested after the user logged in Windows) and gets connected after a single MFA approval.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MFA is still requested to make sure that if someone tries to connect from a stolen laptop even with a leaked username/password, connection to corporate resources would not be possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any Ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 07:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4613735#M574897</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-05-20T07:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - M365 authentication possibilities</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4613840#M574899</link>
      <description>&lt;P&gt;Can this be enough?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/cisco-anyconnect" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/cisco-anyconnect&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 09:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-m365-authentication-possibilities/m-p/4613840#M574899</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-05-20T09:20:42Z</dc:date>
    </item>
  </channel>
</rss>

