<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authenticate on UPN and or SAM Logon in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4726535#M578439</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;ISE 2.7, patch 7&lt;/P&gt;&lt;P&gt;So using Intune&amp;nbsp; for BYOD, some users are having issues connecting, The UPN and SAM name doesn't match, so need to add&amp;nbsp;userprincipalname to the attributes.&lt;/P&gt;&lt;P&gt;My manager is very risk oversee, so just want to check that there is no issues adding "UPN" attribute so the accounts that don't match will authenticate, as to me this just means another field to auth against.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 18:27:58 GMT</pubDate>
    <dc:creator>craiglebutt</dc:creator>
    <dc:date>2022-11-23T18:27:58Z</dc:date>
    <item>
      <title>Authenticate on UPN and or SAM Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4726535#M578439</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;ISE 2.7, patch 7&lt;/P&gt;&lt;P&gt;So using Intune&amp;nbsp; for BYOD, some users are having issues connecting, The UPN and SAM name doesn't match, so need to add&amp;nbsp;userprincipalname to the attributes.&lt;/P&gt;&lt;P&gt;My manager is very risk oversee, so just want to check that there is no issues adding "UPN" attribute so the accounts that don't match will authenticate, as to me this just means another field to auth against.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 18:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4726535#M578439</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2022-11-23T18:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate on UPN and or SAM Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4736690#M578768</link>
      <description>&lt;P&gt;To avoid ambiguity,&amp;nbsp;UPN is preferred as it is supposedly unique for an org. SAM is shorter so easier for inputs. Please balance the benefits based on your organization policies and assessments.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Dec 2022 23:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4736690#M578768</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-12-11T23:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate on UPN and or SAM Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4739999#M578851</link>
      <description>&lt;P&gt;Have you seen our &lt;A href="https://cs.co/ise-webinars" target="_self"&gt;&lt;STRONG&gt;ISE Webinar&lt;/STRONG&gt;&lt;/A&gt; for ISE with Intune?&lt;/P&gt;
&lt;P data-source-line="1054"&gt;▶ &lt;A class="" title="https://youtu.be/iAKyIHFqbgE" href="https://youtu.be/iAKyIHFqbgE" target="_blank" rel="noopener" data-from-md=""&gt;ISE Integration with Intune MDM&lt;/A&gt;&lt;/P&gt;
&lt;P data-source-line="1056"&gt;&lt;A class="" title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=143s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=143s" target="_blank" rel="noopener" data-from-md=""&gt;02:23&lt;/A&gt; Traditional Active Directory vs Azure Active Directory&lt;BR /&gt;&lt;A class="" title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=306s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=306s" target="_blank" rel="noopener" data-from-md=""&gt;05:06&lt;/A&gt; Azure AD Join Types: Registered, Joined, Hybrid Joined&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=420s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=420s" target="_blank" rel="noopener" data-from-md=""&gt;07:00&lt;/A&gt; Intune MDM Enrollment Options&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=548s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=548s" target="_blank" rel="noopener" data-from-md=""&gt;09:08&lt;/A&gt; Windows Autopilot&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=604s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=604s" target="_blank" rel="noopener" data-from-md=""&gt;10:04&lt;/A&gt; Windows Self-Service Out-of-Box Experience (OOBE)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=642s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=642s" target="_blank" rel="noopener" data-from-md=""&gt;10:42&lt;/A&gt; Azure AD Join &amp;amp; Enrollment&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=708s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=708s" target="_blank" rel="noopener" data-from-md=""&gt;11:48&lt;/A&gt; Azure AD Connect to sync on-premise AD&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=818s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=818s" target="_blank" rel="noopener" data-from-md=""&gt;13:38&lt;/A&gt; Azure AD Join vs Hybrid Join: &lt;CODE class="inline-code"&gt;dsregcmd /status&lt;/CODE&gt;&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=907s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=907s" target="_blank" rel="noopener" data-from-md=""&gt;15:07&lt;/A&gt; Intune Certiificate Connector&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=956s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=956s" target="_blank" rel="noopener" data-from-md=""&gt;15:56&lt;/A&gt; Windows Domain Join &amp;amp; Enrollment (with AAD and Intune)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1045s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1045s" target="_blank" rel="noopener" data-from-md=""&gt;17:25&lt;/A&gt; Demo: Tour of Azure AD users and groups, UPNs, devices, registration types, Intune (MEM), compliance, Certificate Connector&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1250s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1250s" target="_blank" rel="noopener" data-from-md=""&gt;20:50&lt;/A&gt; Challenge: Transient MACs (dongle/dock)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1404s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1404s" target="_blank" rel="noopener" data-from-md=""&gt;23:24&lt;/A&gt; Challenge: Random MACs&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1481s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1481s" target="_blank" rel="noopener" data-from-md=""&gt;24:41&lt;/A&gt; ISE 3.1 MDMv3 API and the Globally Unique Identifier (GUID)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1570s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1570s" target="_blank" rel="noopener" data-from-md=""&gt;26:10&lt;/A&gt; Compliance Check with GUID&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1625s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1625s" target="_blank" rel="noopener" data-from-md=""&gt;27:05&lt;/A&gt; Cisco Field Notice FN-72472: GUID required with Intune after Dec 31, 2022&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1705s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1705s" target="_blank" rel="noopener" data-from-md=""&gt;28:25&lt;/A&gt; EAP-TLS Authentication to AD : computer &lt;EM&gt;or&lt;/EM&gt; user) (traditional 802.1X with AD)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1806s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=1806s" target="_blank" rel="noopener" data-from-md=""&gt;30:06&lt;/A&gt; TEAP(EAP-TLS) Authentication in ISE 2.7+ for computer+user (EAP-Chaining)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2013s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2013s" target="_blank" rel="noopener" data-from-md=""&gt;33:33&lt;/A&gt; EAP-TLS Authentication with Hybrid AD+Azure Compliance&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2084s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2084s" target="_blank" rel="noopener" data-from-md=""&gt;34:44&lt;/A&gt; EAP-TLS Authentication with Azure Intune Compliance&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2129s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2129s" target="_blank" rel="noopener" data-from-md=""&gt;35:29&lt;/A&gt; EAP-TTLS+PAP Authentication in ISE 3.0 (no GUID for Intune)&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2191s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2191s" target="_blank" rel="noopener" data-from-md=""&gt;36:31&lt;/A&gt; EAP-TLS Authentication with Azure AD Authorization with Intune Compliance in ISE 3.2&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2284s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2284s" target="_blank" rel="noopener" data-from-md=""&gt;38:04&lt;/A&gt; Intune Lab Overview&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2312s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2312s" target="_blank" rel="noopener" data-from-md=""&gt;38:32&lt;/A&gt; Example ISE 3.1 Policies for AD, Azure, and Intune&lt;BR /&gt;&lt;A title="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2412s" href="https://youtu.be/iAKyIHFqbgE&amp;amp;t=2412s" target="_blank" rel="noopener" data-from-md=""&gt;40:12&lt;/A&gt; Example ISE 3.2 Policies for EAP-TLS with AAD&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 23:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4739999#M578851</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-12-15T23:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate on UPN and or SAM Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4763995#M579451</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I added&amp;nbsp;&lt;SPAN&gt;userprincipalname to the attributes, but this still didn't work, had a cal with TAC, they had issues as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did sort the issue in the end, under Certificate Authentication Profile, I changed the use idenity from certificate attribut to and subject name attribut in the certificate, this resolved the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 10:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-on-upn-and-or-sam-logon/m-p/4763995#M579451</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2023-01-27T10:21:19Z</dc:date>
    </item>
  </channel>
</rss>

