<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can ISE using Azure MFA with Internal User on ISE for authorize on in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750208#M579116</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for answer. And It's one way,&amp;nbsp; ISE can integrate with on-premise AD (AD sync Azure AD) and do authorization condition by group on AD .&amp;nbsp; Because Now I using SAML 2FA on Azure and user it's same information on on-premise AD. This way can possible ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jan 2023 10:29:25 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2023-01-06T10:29:25Z</dc:date>
    <item>
      <title>Can ISE using Azure MFA with Internal User on ISE for authorize only</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749427#M579073</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;
&lt;P&gt;I try to find the solution of Anyconnect integrate with Azure AD and ISE do&amp;nbsp;authorize only . This is solution working fine but ISE integrate with on-premise AD for do condition authorization and If I need use group internal user for do authorization . Can I do that ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference :&amp;nbsp;&lt;A href="https://www.packetswitch.co.uk/cisco-anyconnect-with-azure-ad/" target="_blank"&gt;https://www.packetswitch.co.uk/cisco-anyconnect-with-azure-ad/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-using-azure-mfa-and-ad/td-p/3592900" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-using-azure-mfa-and-ad/td-p/3592900&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jewfcb001_0-1672900921474.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172544i714A3E8EB941C40C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jewfcb001_0-1672900921474.png" alt="jewfcb001_0-1672900921474.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 06:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749427#M579073</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T06:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749522#M579080</link>
      <description>&lt;P&gt;trying to understand your scenario, you looking authentication with Local ISE and Authorisation send to Azure AD ?&lt;/P&gt;
&lt;P&gt;please clarify ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 10:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749522#M579080</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T10:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749530#M579081</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looking for authentication with Azure AD and authorization check from group of internal user for do authorization policy . I'm not sure I explain clear or not?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 10:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749530#M579081</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T10:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749540#M579082</link>
      <description>&lt;P&gt;ok how is your Azure and on Prem AD synched you have any agent ?&lt;/P&gt;
&lt;P&gt;is the users are different on prem and azure cloud ?&lt;/P&gt;
&lt;P&gt;if you have synched user and groups to Azure AD - then ISE can use that AD group for authentication and Authorisation, what is the challange you see here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 11:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749540#M579082</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T11:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749549#M579083</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I understand If I sync ISE with&amp;nbsp; on prem AD and AD replicate&amp;nbsp; with Azure AD can do&amp;nbsp; that .&lt;/P&gt;
&lt;P&gt;My scenario If I will not sync user from AD group. Can I manual create same user with AD in local user in ISE . Can i do that ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 11:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749549#M579083</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T11:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749628#M579085</link>
      <description>&lt;P&gt;If the users and groups are not synched ? how do you validate the user belong to group which is not there ?&lt;/P&gt;
&lt;P&gt;Can I manual create same user with AD in local user in ISE . Can i do that ?&amp;nbsp; - If you create local user in ISE, the users will be Local users - they are not AD users right. - if you looking to authenticate and authz with that database sure you can do so.&lt;/P&gt;
&lt;P&gt;personally your use case not valid. AD user should be located in AD, and belong to Group that is exist to the condition matches here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 13:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749628#M579085</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T13:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749639#M579086</link>
      <description>&lt;P&gt;You can create a local user in ISE and have the user use that for authentication, but this user will not be associated in any way with Active Directory.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749639#M579086</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-05T14:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749653#M579087</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for answer. I see in your answer but the customer have some restriction.&lt;/P&gt;
&lt;P&gt;I looking authentication with Azure AD and condition of authorization I will using the group local&amp;nbsp; user and user in ISE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749653#M579087</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T14:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749657#M579088</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;can create a local user in ISE . you mean authentication i can go Azure AD first and authorization i can go to ISE and check group and user on ISE .&amp;nbsp; My understand correct? If correct , It's my objective.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:12:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749657#M579088</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T14:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749717#M579092</link>
      <description>&lt;P&gt;I do see any option you looking 2 different system - as per i know Either you can use local or Azure AD&amp;nbsp; for Authentication and Authorization&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 15:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749717#M579092</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T15:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749724#M579093</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try to Azure AD for anyconnect authentication first and ISE do authorize with internal local user.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think , I will test first .&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 15:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749724#M579093</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T15:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749765#M579097</link>
      <description>&lt;P&gt;If you also looking 2facto authentication - Like to take advantage of&amp;nbsp; SAML MS authenticator with Azure AD.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 16:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749765#M579097</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T16:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749768#M579098</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I looking for 2FA . Now I integrate SAML with Azure AD&amp;nbsp; And after authentication I need ISE do authorize but in condition on ISE I need the local user group in ISE for do that . that's all my requirement.&lt;/P&gt;
&lt;P&gt;I'm not sure Are you got my point ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 16:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749768#M579098</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-05T16:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749916#M579107</link>
      <description>&lt;P&gt;No, that is not what I meant.&amp;nbsp; you need to either use an external user or an internal user.&amp;nbsp; If you are using an external user but want to match on something other than an Active Directory group or similar, you would need to install a posture agent on the client machine and then match on something local on the machine that the agent can identify.&lt;/P&gt;
&lt;P&gt;Matching on a user group local to the ISE is not possible as far as I know.&amp;nbsp; There is no way to associate an external user with a local group that I can see.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 21:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749916#M579107</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-05T21:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749919#M579108</link>
      <description>&lt;P&gt;In&amp;nbsp; your own terms what you mean by Authorization -&lt;STRONG&gt;"authorization i can go to ISE"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;as we repeatedly mentioned that is not possible,&lt;/P&gt;
&lt;P&gt;Based on the condition matched&amp;nbsp; - ISE will have policies - on what to access and what to not access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 21:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749919#M579108</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-05T21:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749982#M579110</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I mean If authentication via 2FA Azure AD and FW will do authorize to ISE and ISE do authorize , condition in authorize I using internal user&amp;nbsp; internal. The user, I will create it same in AD instead sync user from AD (Restrictions from the customer). Are you clear in my explain?&lt;/P&gt;
&lt;P&gt;Please see the detail below again.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jewfcb001_1-1672970135540.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172600iF43D2C496FE48D1E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jewfcb001_1-1672970135540.png" alt="jewfcb001_1-1672970135540.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 01:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749982#M579110</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-06T01:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749986#M579111</link>
      <description>&lt;P&gt;As Picture below It's my objective. I understand It's my sense but restrictions from the customer.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jewfcb001_0-1672970105703.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172599i2E888C0B1F7A0CA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jewfcb001_0-1672970105703.png" alt="jewfcb001_0-1672970105703.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 01:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4749986#M579111</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-06T01:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750196#M579113</link>
      <description>&lt;P&gt;If the user already verified and he is in AD, what is the point of redoing same verification ?&lt;/P&gt;
&lt;P&gt;Looks like we are going circle here - spending enough time discussing the same situation again and again.&lt;/P&gt;
&lt;P&gt;Personally the solution not work - the use case&amp;nbsp; not intedent to design like that.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp; suggested you can look posture module to validate after 2Facto done.&lt;/P&gt;
&lt;P&gt;I would suggest to contact Local Cisco partner and Contact TAC -&amp;nbsp; validate the information provided here.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 10:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750196#M579113</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-06T10:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750199#M579114</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 10:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750199#M579114</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-01-06T10:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE using Azure MFA with Internal User on ISE for authorize on</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750204#M579115</link>
      <description>&lt;P&gt;Even if you configure the same user name and groups on the ISE it will still be different from the user you are authenticating with so there is nothing associating the user you are authenticating with to the objects you create in ISE.&amp;nbsp; So, you have a couple options here.&lt;/P&gt;
&lt;P&gt;1. install a posture agent on the end client PC and authorize the user based on some value configured in the PC&lt;/P&gt;
&lt;P&gt;2. use certificate authentication with MFA.&amp;nbsp; This way you can authorize the user based on values within the certificate.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 10:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-using-azure-mfa-with-internal-user-on-ise-for-authorize/m-p/4750204#M579115</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-06T10:23:02Z</dc:date>
    </item>
  </channel>
</rss>

