<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Integration with Entra-joined Devices/Users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5170713#M591634</link>
    <description>&lt;P&gt;I would like to migrate the rules as similar as possible.&lt;BR /&gt;Given the limitations of Entra-id it seems to me that the only more similar way is to check certain values within the certificate, but those values have to be created first on Entra-id, so yes, there is no direct integration with Entra-id, but, however,&amp;nbsp; those parameters on the certificates have to be congruent between Ise and Entra-id&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2024 07:34:10 GMT</pubDate>
    <dc:creator>MaErre21325</dc:creator>
    <dc:date>2024-09-04T07:34:10Z</dc:date>
    <item>
      <title>ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5057792#M588593</link>
      <description>&lt;P&gt;My organization is working on migration path to Win11 (Entra joined), with hybrid user accounts. According to the below posting, it was mentioned that TEAP (EAP-TLS) is not supported for Computer authentication or EAP-Chaining.&lt;/P&gt;&lt;P&gt;&lt;LI-MESSAGE title="Cisco ISE with Microsoft Active Directory, Azure AD, and Intune" uid="4763635" url="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/m-p/4763635#U4763635" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two questions about this;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is this a limitation of ISE or with Windows11 being Entra joined?&amp;nbsp; If ISE, could you please explain why EAP-Chaining and computer authentication are not supported?&lt;/LI&gt;&lt;LI&gt;We are currently using TEAP to solve the "chick and egg" problem outlined in the below posting.&amp;nbsp; If TEAP cannot be used in an Entra joined environment, then what options are available to ensure that a user logging into a computer for the first time is able to build a user profile with certificate issuance, for user authentication?&lt;BR /&gt;&lt;LI-MESSAGE title="EAP-TEAP: First time user login/chicken &amp;amp;amp; egg scenario" uid="4475351" url="https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/m-p/4475351#U4475351" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 20:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5057792#M588593</guid>
      <dc:creator>GregoryLeggett</dc:creator>
      <dc:date>2024-04-05T20:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5059470#M588605</link>
      <description>&lt;P&gt;Authorization of an Entra Joined Device is not currently possible in ISE, and neither is EAP Chaining an authenticated User session and Computer session. This is specifically stated in the&amp;nbsp;ISE 3.2 Release Notes&lt;/P&gt;
&lt;P&gt;With Windows 11, most organisations are moving from the legacy on-corporate-network PC staging/build process that is controlled by SCCM and uses the PXE boot process to a&amp;nbsp;Windows Autopilot process. For Autopilot, the user would just need a bare internet connection to complete the build, so this could be potentially be accomplished by connecting to a Guest BYOD portal or hotspot of some kind. Part of the AutoPilot process would be enrolment with Intune which would also enrol the Device/User certificates, after which point the user could connect to the secure Corporate network.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 00:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5059470#M588605</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-04-08T00:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169421#M591596</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;i've been asked to migrate our ise deployment from traditional ad to entra id.&lt;BR /&gt;i read the following document: "Configure ISE 3.0 REST ID with Azure Active Directory" at this link:&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;but it is using eap-ttls, i'm wondering if i can still use eap-tls as in my actual working setup...&lt;BR /&gt;furthermore, as i understand, rest id is the only method to integrate cisco ise with entra id.&lt;/P&gt;
&lt;P&gt;then i found this guide "Configure ISE 3.2 EAP-TLS with Microsoft Azure Active Directory"&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html#toc-hId--1070241705" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html#toc-hId--1070241705&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and is using eap-tls, so i'm a little bit confused about what to do....&lt;/P&gt;
&lt;P&gt;Am i able to integrate ise and entra id but using eap-tls instead of eap-ttls in my authorization rules?&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;
&lt;P&gt;bye&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 13:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169421#M591596</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2024-09-02T13:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169565#M591600</link>
      <description>&lt;P&gt;Yes, as stated in the "&lt;SPAN&gt;Configure ISE 3.2 EAP-TLS with Microsoft Azure Active Directory" you referenced, you can use the REST ID function in ISE version 3.2 and higher to authorize a User against Entra ID. The Entra ID App Registration configuration would be the same as shown in the "Configure ISE 3.0 REST ID with Azure Active Directory" guide, except you would not need to enable the ROPC option shown in Step/Figure 9 of that document.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You might also see this blog for current options related to ISE and Entra ID.&lt;BR /&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635" target="_blank"&gt;Cisco ISE with Microsoft Active Directory, Entra ID, and Intune&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 22:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169565#M591600</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-09-02T22:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169766#M591606</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;the more i read the document the more i get confused.&lt;BR /&gt;These are my actual ruIes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MaErre21325_2-1725356121607.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227619i90F823DD0B5B6E84/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MaErre21325_2-1725356121607.png" alt="MaErre21325_2-1725356121607.png" /&gt;&lt;/span&gt;&lt;BR /&gt;in order to migrate them i should reference to "Authentication/Authorization of an Entra Joined Device using EAP-TLS" guide (we do device authentication by checking if the certificate is released by our CA and the for the authorization we check if the device is matching the AD groups).&lt;BR /&gt;For the authorizaton rule i only need to add the policy value as per the following screenshot:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MaErre21325_0-1725355675826.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227616i4B27D8F975F3DD60/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MaErre21325_0-1725355675826.png" alt="MaErre21325_0-1725355675826.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In this case i don't need to configure the REST ID function, am i correct? In this way Ise should check only if this value matches the value i want.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Bye&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 10:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5169766#M591606</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2024-09-03T10:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5170382#M591619</link>
      <description>&lt;P&gt;There is currently no comparable authorization of a Device group/attribute against Entra ID as your current use case with AD. If all you are planning to do is Authenticate and Authorize a Device based simply on values in the certificate it presents to ISE for EAP-TLS and trust of that certificate chain, then you would not need any integration with Entra ID.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 22:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5170382#M591619</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-09-03T22:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5170713#M591634</link>
      <description>&lt;P&gt;I would like to migrate the rules as similar as possible.&lt;BR /&gt;Given the limitations of Entra-id it seems to me that the only more similar way is to check certain values within the certificate, but those values have to be created first on Entra-id, so yes, there is no direct integration with Entra-id, but, however,&amp;nbsp; those parameters on the certificates have to be congruent between Ise and Entra-id&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 07:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5170713#M591634</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2024-09-04T07:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5213581#M592596</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-1884295217" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-1884295217&lt;/A&gt;&amp;nbsp; This seems to show it is now possible after fixing the bug&amp;nbsp;&lt;A class="xref" href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd34467" target="_blank" rel="noopener" data-config-metrics-group="dest_pg_body" data-config-metrics-title="dest_pg_body_links"&gt;CSCwd34467&lt;/A&gt;&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 11:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5213581#M592596</guid>
      <dc:creator>SamW1</dc:creator>
      <dc:date>2024-10-23T11:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5213937#M592609</link>
      <description>&lt;P&gt;Yes, as stated in that document it is possible to use TEAP(EAP-TLS) with the User authorization against Entra ID. It is still currently not possible to perform authorization of a Device against Entra ID (also stated in that document).&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 21:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5213937#M592609</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-10-23T21:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214591#M592651</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt; - Is device authorisation going to be supported with ISE, so the ability to lookup the basic device object in Entra during EAP-TLS/TEAP-TLS auth using the device's GUID to check that a) its a present/valid object and b) to return any device attributes to allow ISE to select an appropiate result, or is this purley a limitation in Entra that is not going to be changed any time soon?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214591#M592651</guid>
      <dc:creator>packet2020</dc:creator>
      <dc:date>2024-10-24T15:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214604#M592654</link>
      <description>&lt;P&gt;Just checked with a TME:&lt;/P&gt;
&lt;P&gt;I got this response today from a Cisco SE for ISE....&lt;/P&gt;
&lt;P&gt;Device authorization in Entra ID is planned for 3.4 Patch 2 (but could slip, all normal patch caveats apply)&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214604#M592654</guid>
      <dc:creator>SamW1</dc:creator>
      <dc:date>2024-10-24T15:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214612#M592655</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE 3.4 P2 - Machine Authz in Entra ID.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232234iBF51F9CA5D8D36A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ISE 3.4 P2 - Machine Authz in Entra ID.png" alt="ISE 3.4 P2 - Machine Authz in Entra ID.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I read in a "what's new in ISE 3.4 ..." series, that Machine authorization, in Entra ID, will be supported in 3.4 &lt;STRONG&gt;patch 2&lt;/STRONG&gt; (which is planned for Q1/2025).&lt;/P&gt;&lt;P&gt;Can't find back the link for source though.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 16:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214612#M592655</guid>
      <dc:creator>RamsesDE</dc:creator>
      <dc:date>2024-10-24T16:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214769#M592662</link>
      <description>&lt;P&gt;In general, this is something the developers are working on for an enhancement but&amp;nbsp;implementing it has proven much more difficult than originally expected due to the difficulty of identifying a computer versus user session purely by the certificate presented as certificate templates vary from customer to customer.&lt;/P&gt;
&lt;P&gt;While the current target may be for 3.4 patch 2, these dates should not expected as development is still in progress and extensive testing will likely need to be done to ensure the changes do not affect other functions.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 22:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5214769#M592662</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-10-24T22:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5260659#M595002</link>
      <description>&lt;P&gt;Hello and happy Friday!&lt;/P&gt;
&lt;P&gt;Any update on TEAP-TLS Chaining with Entra-ID?&amp;nbsp; I read ISE 3.4 patch 2?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 16:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5260659#M595002</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2025-02-14T16:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5261153#M595016</link>
      <description>&lt;P&gt;The feature for Device Authorization against Entra ID is no longer expected to be available until the release of ISE 3.5. No ETA can be provided, but you're likely looking at around June-July timeframe. It will likely be back-ported to a patch in 3.4 that will release after the FCS of 3.5.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2025 20:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5261153#M595016</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-02-16T20:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5261550#M595037</link>
      <description>&lt;P&gt;Thanks for the info Greg.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 18:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5261550#M595037</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2025-02-17T18:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5271331#M595487</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;I am bit confused... if&amp;nbsp;TEAP(EAP-TLS) and EAP-FAST(EAP-TLS) with EAP Chaining are supported for this Entra AD flow from ISE 3.2 patch 5 and ISE 3.3 patch 1 due to the fix implemented by bugID&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd34467" target="_blank" rel="noopener nofollow noreferrer"&gt;CSCwd34467&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Then what is the use case of Machine authentication function going to be release on ISE 3.5. Without ISE 3.5 can we use this ?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 13:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5271331#M595487</guid>
      <dc:creator>hasitha siriwardhana</dc:creator>
      <dc:date>2025-03-14T13:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5300110#M596806</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have this problem where i need to do the user lookup for group membership in Entra ID for authorization rule in ISE using Rest ID instead of ROPC. I do not want to enable ROPC in Azure for application i setup for ISE. However ISE is not able to get the user group membership and failing the authorization.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;Can you help me what could be the issue here in ISE where ISE is not able to fetch User group membership from Entra ID. I am using ISE 3.2 Patch 7.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 16:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5300110#M596806</guid>
      <dc:creator>aaggarwal12</dc:creator>
      <dc:date>2025-06-17T16:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5326677#M598021</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;Has this feature for EAP chaining (Device and User Authentication) now been added to ICE 3.5. Can you share a link to relevant documentation that shows support with Entra ID.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 06:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5326677#M598021</guid>
      <dc:creator>Kenny Thompson</dc:creator>
      <dc:date>2025-09-03T06:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Entra-joined Devices/Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5326764#M598029</link>
      <description>&lt;P&gt;I have found the Release Notes for 3.5 even when they are not referenced in Cisco URL:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-identity-services-engine-release-notes-35.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/release_notes/cisco-identity-services-engine-release-notes-35.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;See this section:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavonM_0-1756896282892.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251316iABD6C2138242ED03/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavonM_0-1756896282892.png" alt="JPavonM_0-1756896282892.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/admin_guide/b_ise_admin_3_5/b_ISE_admin_asset_visibility.html#task_hbc_rwl_qtb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/admin_guide/b_ise_admin_3_5/b_ISE_admin_asset_visibility.html#task_hbc_rwl_qtb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 10:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-entra-joined-devices-users/m-p/5326764#M598029</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2025-09-03T10:45:00Z</dc:date>
    </item>
  </channel>
</rss>

