<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.4 + Guest Portal Azure disable MFA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4617467#M574954</link>
    <description>&lt;P&gt;Hi Greg,&lt;/P&gt;
&lt;P&gt;So if we want to disable or enable the MFA we should upgrade to ISE 3.0 as the Cisco Deck provide?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yeah sure we want to upgrade but ISE 3.0 licensing is different. Thanks for remind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2022 11:14:58 GMT</pubDate>
    <dc:creator>iman.yuliarto</dc:creator>
    <dc:date>2022-05-25T11:14:58Z</dc:date>
    <item>
      <title>Cisco ISE 2.4 + Guest Portal Azure disable MFA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4616266#M574932</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have an issue with Cisco ISE 2.4.0.357 patch 13 + wireless Guest portal to Azure with SAML, the configuration was work properly until last week.&lt;/P&gt;
&lt;P&gt;We have changes at last month to enable MFA on all azure authentication, but the issue just appears last week.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the issue is :&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bf285612-b6ce-4852-ac73-d179d69e43cc.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151844iDB4CE80DDAA50BFC/image-size/large?v=v2&amp;amp;px=999" role="button" title="bf285612-b6ce-4852-ac73-d179d69e43cc.jpeg" alt="bf285612-b6ce-4852-ac73-d179d69e43cc.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorimanyuliarto_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;after we try to research this, we found the link&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/error-code-aadsts75011-auth-method-mismatch" target="_self"&gt;https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/error-code-aadsts75011-auth-method-mismatch&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also this cisco live pdf at page 32 &lt;A href="https://community.cisco.com/kxiwq67737/attachments/kxiwq67737/documents-securite/9/1/Webcast_ISE_Pujol_mar09_2021.pdf" target="_self"&gt;https://community.cisco.com/kxiwq67737/attachments/kxiwq67737/documents-securite/9/1/Webcast_ISE_Pujol_mar09_2021.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but we can't find on the ISE how to modify SAML Header request to Azure. we need to remove &lt;CODE&gt;RequestedAuthnContext&lt;/CODE&gt; as suggested by Microsoft and Cisco&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We want to disable Azure MFA only for Cisco ISE communication.&lt;/P&gt;
&lt;P&gt;did anyone have face this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 10:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4616266#M574932</guid>
      <dc:creator>iman.yuliarto</dc:creator>
      <dc:date>2022-05-24T10:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 + Guest Portal Azure disable MFA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4616857#M574944</link>
      <description>&lt;P&gt;The Cisco deck you shared specifically references ISE version 3.0. This is an enhancement that would not be present in your current version of ISE 2.4. You will need to upgrade your ISE deployment to take advantage of this feature enhancement.&lt;/P&gt;
&lt;P&gt;You should also be aware that &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-743964.html" target="_blank" rel="noopener"&gt;ISE version 2.4 reaches End of Support in Dec 2022&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 23:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4616857#M574944</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-05-24T23:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 + Guest Portal Azure disable MFA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4617467#M574954</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;
&lt;P&gt;So if we want to disable or enable the MFA we should upgrade to ISE 3.0 as the Cisco Deck provide?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yeah sure we want to upgrade but ISE 3.0 licensing is different. Thanks for remind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 11:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-guest-portal-azure-disable-mfa/m-p/4617467#M574954</guid>
      <dc:creator>iman.yuliarto</dc:creator>
      <dc:date>2022-05-25T11:14:58Z</dc:date>
    </item>
  </channel>
</rss>

