<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ExternalGroups in REST ID (Azure AD) in Authorization Policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298148#M596725</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;
&lt;P&gt;In ISE 3.2 (standalone node) have set up REST ID with Azure following all I found in this two documents&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.htmlù" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;All steps seems to work fine, and the "test connection" from REST ID config page works fine.&lt;/P&gt;
&lt;P&gt;Once I use the ExternalGroups as extenral identity source in a AUthorization Policy, however, I can see in the live logs the query for ExternalGroups&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="content_table_steps" border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR class="content_table_steps_highlight"&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP - XXXXXX_Azure_AD.ExternalGroups&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;yet it still can't match user to group.&lt;/P&gt;
&lt;P&gt;Is there something specific that I may be missing? The REST ID setup guide refers to 3.0, is there anything different in 3.2? I have REST rather than REST (ROPC) in the&amp;nbsp;&lt;SPAN&gt;External Identity Sources setup page, but the contents are similar... I seems to be missing the 4.e configuration in ISE, "Username Suffix" I don't know if there's anything different in this version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can anyone please help in this regard? Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fabio&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jun 2025 15:02:10 GMT</pubDate>
    <dc:creator>fabioairoldi</dc:creator>
    <dc:date>2025-06-10T15:02:10Z</dc:date>
    <item>
      <title>ExternalGroups in REST ID (Azure AD) in Authorization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298148#M596725</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;
&lt;P&gt;In ISE 3.2 (standalone node) have set up REST ID with Azure following all I found in this two documents&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.htmlù" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216182-configure-ise-3-0-rest-id-with-azure-act.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;All steps seems to work fine, and the "test connection" from REST ID config page works fine.&lt;/P&gt;
&lt;P&gt;Once I use the ExternalGroups as extenral identity source in a AUthorization Policy, however, I can see in the live logs the query for ExternalGroups&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="content_table_steps" border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR class="content_table_steps_highlight"&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP - XXXXXX_Azure_AD.ExternalGroups&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;yet it still can't match user to group.&lt;/P&gt;
&lt;P&gt;Is there something specific that I may be missing? The REST ID setup guide refers to 3.0, is there anything different in 3.2? I have REST rather than REST (ROPC) in the&amp;nbsp;&lt;SPAN&gt;External Identity Sources setup page, but the contents are similar... I seems to be missing the 4.e configuration in ISE, "Username Suffix" I don't know if there's anything different in this version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can anyone please help in this regard? Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fabio&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 15:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298148#M596725</guid>
      <dc:creator>fabioairoldi</dc:creator>
      <dc:date>2025-06-10T15:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: ExternalGroups in REST ID (Azure AD) in Authorization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298276#M596735</link>
      <description>&lt;P&gt;If you're using EAP-TLS and User Authorization against Entra ID, the documents you shared should have everything you need.&lt;/P&gt;
&lt;P&gt;For the EAP-TLS with REST ID, you do not need to enable ROPC on the App Registration. ROPC only applies to the EAP-TTLS(PAP)&amp;nbsp; or RAVPN use cases.&lt;/P&gt;
&lt;P&gt;The Username Suffix is appended to the username by ISE before sending that to the Graph API for lookup when using the ROPC flow.&lt;/P&gt;
&lt;P&gt;When using the EAP-TLS flow with ISE 3.2+ the full UPN must be provided in the certificate (CN or SAN) and used by ISE for identity (as defined in the Certificate Authentication Profile). ISE can only perform the lookup against the Graph API using the UPN.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 04:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298276#M596735</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-06-11T04:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: ExternalGroups in REST ID (Azure AD) in Authorization Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298296#M596740</link>
      <description>&lt;P&gt;That's actually it! I was checking against an attribute other than UPN, by changing the certificate structure and checking against UPN it now works, thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/externalgroups-in-rest-id-azure-ad-in-authorization-policy/m-p/5298296#M596740</guid>
      <dc:creator>fabioairoldi</dc:creator>
      <dc:date>2025-06-11T06:44:10Z</dc:date>
    </item>
  </channel>
</rss>

