<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE OKTA SAML Integration for Admin Access to Web GUI in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941442#M584644</link>
    <description>&lt;P&gt;Thank you! I will note that I had to deviate from the instructions under the sections&amp;nbsp;&lt;STRONG&gt;7. Configure Active Directory Group Attribute&lt;/STRONG&gt; and &lt;STRONG&gt;Step 4. Configure SAML Groups on ISE&lt;/STRONG&gt;. Under &lt;STRONG&gt;7. Configure Active Directory Group Attribute&lt;/STRONG&gt;, instead of giving the group claim a custom name, I had to leave the claim name for groups as the default, &lt;A href="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups," target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups,&lt;/A&gt; and then under Step 4. Configure SAML Groups on ISE, for the group membership attribute, instead of just putting "groups", I had to put&amp;nbsp;&lt;A href="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups" target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups&lt;/A&gt; and then the group mapping worked.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2023 23:21:44 GMT</pubDate>
    <dc:creator>jmorton1</dc:creator>
    <dc:date>2023-10-16T23:21:44Z</dc:date>
    <item>
      <title>ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3880212#M471952</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a customer that has asked whether we can add two-factor authentication to the Admin Access side of ISE via OKTA as a SAML provider. I have only ever configured this with native AD integration based on a security group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea if the Admin Access (access to the ISE GUI) can be integrated with OKTA?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISE 2.6 guide mentions only some of the actual portals for end users, not administrators.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 18:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3880212#M471952</guid>
      <dc:creator>jordanburnett</dc:creator>
      <dc:date>2019-06-26T18:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3880398#M471955</link>
      <description>&lt;P&gt;No, not currently. SAML is only supported for Guest, Mydevices, Sponsor, and Certificate provisioning portal.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 00:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3880398#M471955</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-06-27T00:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3882149#M471958</link>
      <description>&lt;P&gt;Thanks! Is there any way to do multi-factor authentication for Admin Access?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 12:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3882149#M471958</guid>
      <dc:creator>jordanburnett</dc:creator>
      <dc:date>2019-06-30T12:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3882164#M471962</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/310861"&gt;@jordanburnett&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;... Is there any way to do multi-factor authentication for Admin Access?&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Yes, MFA does not require SAML.&amp;nbsp;&lt;SPAN&gt;See an example how it can be done at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/mfa-for-ise-admin-access/td-p/3728518" target="_blank" rel="noopener"&gt;Solved: MFA for ISE admin access? - Cisco Community&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 14:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/3882164#M471962</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-06-30T14:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941261#M584628</link>
      <description>&lt;P&gt;Does anyone know if this has changed by chance? It has been 4 years. I was hoping with could do SAML for the admin portal of ISE 3.3&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941261#M584628</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2023-10-16T16:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941390#M584641</link>
      <description>&lt;P&gt;Yes, SAML is supported for authentication of the Admin GUI. See this example and see if you can tweak it for your use case.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217342-configure-ise-3-1-ise-gui-admin-login-fl.html" target="_blank" rel="noopener"&gt;Configure ISE 3.1 ISE GUI Admin Log in Flow via SAML SSO Integration with Azure AD&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 21:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941390#M584641</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-10-16T21:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941442#M584644</link>
      <description>&lt;P&gt;Thank you! I will note that I had to deviate from the instructions under the sections&amp;nbsp;&lt;STRONG&gt;7. Configure Active Directory Group Attribute&lt;/STRONG&gt; and &lt;STRONG&gt;Step 4. Configure SAML Groups on ISE&lt;/STRONG&gt;. Under &lt;STRONG&gt;7. Configure Active Directory Group Attribute&lt;/STRONG&gt;, instead of giving the group claim a custom name, I had to leave the claim name for groups as the default, &lt;A href="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups," target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups,&lt;/A&gt; and then under Step 4. Configure SAML Groups on ISE, for the group membership attribute, instead of just putting "groups", I had to put&amp;nbsp;&lt;A href="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups" target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups&lt;/A&gt; and then the group mapping worked.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 23:21:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/4941442#M584644</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2023-10-16T23:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OKTA SAML Integration for Admin Access to Web GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/5221657#M593068</link>
      <description>&lt;P&gt;Hi Jmorton1-&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; Sorry Re-read and saw you are probably using Azure AD and not another SAML provider.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 18:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-saml-integration-for-admin-access-to-web-gui/m-p/5221657#M593068</guid>
      <dc:creator>BrianRoberson</dc:creator>
      <dc:date>2024-11-07T18:33:55Z</dc:date>
    </item>
  </channel>
</rss>

