<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML EntraID Guest access not loading Microsoft login page in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314792#M597493</link>
    <description>&lt;P&gt;You have logs also attached.&lt;/P&gt;&lt;P&gt;But I think that you are wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should be able to see this traffic on my FW - check flow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanijelTurkovic_0-1753706729355.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249316i95FE07F61310E1ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanijelTurkovic_0-1753706729355.png" alt="DanijelTurkovic_0-1753706729355.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is why you need to use pre auth URL filter list to allow this traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jul 2025 12:46:29 GMT</pubDate>
    <dc:creator>Danijel Turkovic</dc:creator>
    <dc:date>2025-07-28T12:46:29Z</dc:date>
    <item>
      <title>SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314767#M597488</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we setup ISE and Entra ID integration with SAML.&lt;/P&gt;&lt;P&gt;Access work fine for notebooks (tested on 10+ devices), but I am running with issue on some mobile devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some Android and iPhone device after redirect to login.microsoftonline.com page are not opening - blank screen with url only - without any error. Let's say from tested 10 device half is working and other half stuck on same problem (loading Microsoft login page).&lt;/P&gt;&lt;P&gt;I've check firewall and I can see flow to Internet from problematic client IP pointing to login.microsoftonline.com (TCP reset from client side and tcp-fin)&lt;/P&gt;&lt;P&gt;Also my pre-auth URL filter list is not working if I put deny statement -&amp;gt; in this guide there is deny statement for ULR filter list pointing to Microsoft login page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-byod-flow-using-entra-id/ta-p/4400675" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-byod-flow-using-entra-id/ta-p/4400675&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any hint where to look further?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 12:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314767#M597488</guid>
      <dc:creator>Danijel Turkovic</dc:creator>
      <dc:date>2025-07-28T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314773#M597490</link>
      <description>&lt;P&gt;Try open url in browser&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See if the page is secure or not.&lt;/P&gt;
&lt;P&gt;If not you need to add CA cert&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 11:59:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314773#M597490</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-28T11:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314774#M597491</link>
      <description>&lt;P&gt;Page is secured.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 12:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314774#M597491</guid>
      <dc:creator>Danijel Turkovic</dc:creator>
      <dc:date>2025-07-28T12:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314786#M597492</link>
      <description>&lt;P&gt;You check traffic between client and Microsoft in FW ?&lt;/P&gt;
&lt;P&gt;Traffic must not pass via FW before user authc&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 12:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314786#M597492</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-28T12:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314792#M597493</link>
      <description>&lt;P&gt;You have logs also attached.&lt;/P&gt;&lt;P&gt;But I think that you are wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should be able to see this traffic on my FW - check flow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanijelTurkovic_0-1753706729355.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249316i95FE07F61310E1ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanijelTurkovic_0-1753706729355.png" alt="DanijelTurkovic_0-1753706729355.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is why you need to use pre auth URL filter list to allow this traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 12:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314792#M597493</guid>
      <dc:creator>Danijel Turkovic</dc:creator>
      <dc:date>2025-07-28T12:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314833#M597501</link>
      <description>&lt;P&gt;I've think I resolve my problem with adding new URL list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like this list from Greg guide need to be extended for Android and iPhone&amp;nbsp;&lt;/P&gt;&lt;P&gt;So from this&lt;/P&gt;&lt;PRE&gt;login.microsoftonline.com
aadcdn.microsoftonline-p.com
aadcdn.msauth.net&lt;/PRE&gt;&lt;P&gt;I've increase list to this - found this on forum&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;login.live.com
go.microsoft.com
aadcdn.msauth.net
aadcdn.msftauth.net
graph.microsoft.com
app.vssps.dev.azure.com
login.microsoftonline.com
app.vssps.visualstudio.com
login.microsoftonline-p.com
management.core.windows.net
secure.aadcdn.microsoftonline-p.com&lt;/PRE&gt;&lt;P&gt;And now problematic phones are opening login.microsoftonline.com without any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5314833#M597501</guid>
      <dc:creator>Danijel Turkovic</dc:creator>
      <dc:date>2025-07-28T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: SAML EntraID Guest access not loading Microsoft login page</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5315005#M597508</link>
      <description>&lt;P&gt;Thanks for the update&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1899778"&gt;@Danijel Turkovic&lt;/a&gt;. I've updated my blog post with this list as well.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 22:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-entraid-guest-access-not-loading-microsoft-login-page/m-p/5315005#M597508</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-07-28T22:08:55Z</dc:date>
    </item>
  </channel>
</rss>

