<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 3.2 EAP-TLS Azure AD permission error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726680#M578448</link>
    <description>&lt;P&gt;We are implementing Azure AD EAP-TLS authentication on ISE 3.2 using the following guide:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We have hit an issue where in the rest-id-store.log we are getting the following error (Insufficient privileges to complete the operation):&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;,799 ERROR [http-nio-9601-exec-5][[]] cisco.ise.ropc.utilities.RestUtility -::::- Error response in 'GET' request. Status - '403'. Error - '{"error":{"code":"Authorization_RequestDenied","message":"Insufficient privileges to complete the operation&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In the ISE 3.2 demonstration video, the same error occurs and the presentor is unable to get it working (Time 29.40) and does not provide any resolution:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.youtube.com/watch?v=857hIkxkEAU" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=857hIkxkEAU&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Has anyone managed to get this working and solve the 403 permission error or does EAP-TLS on 3.2 not work?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 15:21:45 GMT</pubDate>
    <dc:creator>seankin</dc:creator>
    <dc:date>2022-11-23T15:21:45Z</dc:date>
    <item>
      <title>ISE 3.2 EAP-TLS Azure AD permission error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726680#M578448</link>
      <description>&lt;P&gt;We are implementing Azure AD EAP-TLS authentication on ISE 3.2 using the following guide:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We have hit an issue where in the rest-id-store.log we are getting the following error (Insufficient privileges to complete the operation):&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;,799 ERROR [http-nio-9601-exec-5][[]] cisco.ise.ropc.utilities.RestUtility -::::- Error response in 'GET' request. Status - '403'. Error - '{"error":{"code":"Authorization_RequestDenied","message":"Insufficient privileges to complete the operation&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In the ISE 3.2 demonstration video, the same error occurs and the presentor is unable to get it working (Time 29.40) and does not provide any resolution:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.youtube.com/watch?v=857hIkxkEAU" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=857hIkxkEAU&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Has anyone managed to get this working and solve the 403 permission error or does EAP-TLS on 3.2 not work?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 15:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726680#M578448</guid>
      <dc:creator>seankin</dc:creator>
      <dc:date>2022-11-23T15:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.2 EAP-TLS Azure AD permission error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726709#M578450</link>
      <description>&lt;P&gt;Yes, I included the solution in the &lt;STRONG&gt;Show Notes&lt;/STRONG&gt; of that YouTube video&amp;nbsp; 8-)&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt;The permissions problem in the demo was 1 additional API Permission in Azure Active Directory was required to make it work. The 3 required permissions are &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;- Group.Read.All&lt;BR /&gt;- User.Read&lt;BR /&gt;- User.Read.All&amp;nbsp; ◁◁◁ This was missing!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE 3.2 - Azure AD Permissions for EAP-TLS.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/168843iFB974B9A02B9987C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE 3.2 - Azure AD Permissions for EAP-TLS.png" alt="ISE 3.2 - Azure AD Permissions for EAP-TLS.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 16:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726709#M578450</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-11-23T16:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.2 EAP-TLS Azure AD permission error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726711#M578451</link>
      <description>&lt;P&gt;Brilliant! Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 16:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4726711#M578451</guid>
      <dc:creator>seankin</dc:creator>
      <dc:date>2022-11-23T16:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.2 EAP-TLS Azure AD permission error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4795672#M580537</link>
      <description>&lt;P&gt;Hi there. This is EAP-TLS with Azure AD users. Would this also work with Azure AD computer accounts as well?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 14:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4795672#M580537</guid>
      <dc:creator>Jan Junker</dc:creator>
      <dc:date>2023-03-16T14:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.2 EAP-TLS Azure AD permission error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4796016#M580557</link>
      <description>&lt;P&gt;There is no such thing as an Azure AD 'Computer' account. See this document for more information.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635" target="_blank" rel="noopener"&gt;Cisco ISE with Microsoft Active Directory, Azure AD, and Intune&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 21:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-2-eap-tls-azure-ad-permission-error/m-p/4796016#M580557</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-03-16T21:04:43Z</dc:date>
    </item>
  </channel>
</rss>

