<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 3.5 Entra ID Authorization Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349028#M599052</link>
    <description>&lt;P&gt;Hello! I followed this link/guide:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We checked all the permissions for the Entra ID, ISE policies, and nothing. The documentation advises disabling Microsoft MFA, otherwise it doesn't work. We did this and the error persists. The REST within ISE is communicating normally with the tenant and the Entra ID app registration. We checked everything related to certificates; we inserted the certificate within the Entra ID app registration, issued a new certificate and a new chain, and imported it into ISE. We don't believe the problem is with certificates, because if I try to authenticate using a local Active Directory, for example: some domain user, it works with a different authentication policy and a different authorization policy.&lt;/P&gt;
&lt;P&gt;Error code: 5400 Authentication failed&lt;BR /&gt;Failure Reason 12976 EAP-TTLS authentication failed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Nov 2025 13:02:49 GMT</pubDate>
    <dc:creator>Andre-Teixeira</dc:creator>
    <dc:date>2025-11-21T13:02:49Z</dc:date>
    <item>
      <title>Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5344955#M598828</link>
      <description>&lt;P&gt;I have a PoC in my customer for Cisco ISE integration with Entra ID and currently I test it first on my lab.&lt;BR /&gt;My customer only has Entra ID for the IDP and no on-prem AD.&lt;BR /&gt;I use EAP-TLS and using ISE Certificate Provisioning Portal to generate endpoint cert.&lt;BR /&gt;From the live log, I see that Authentication Result have passed but it failed due to Rejected per authorization profile.&lt;BR /&gt;What step do I miss here?&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 09:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5344955#M598828</guid>
      <dc:creator>andrianusfranky</dc:creator>
      <dc:date>2025-11-06T09:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5344964#M598829</link>
      <description>&lt;P&gt;It's interesting to see that on the live log it says authentication failed when the authentication has actually passed. Have you tried to remove the authentication status condition from the authorization rule and see if that makes any difference? also, please check this link which has bunch of helpful details:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635/show-comments/true#toc-hId--2092417075" target="_blank"&gt;Cisco ISE with Microsoft Active Directory, Entra ID, and Intune - Cisco Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 10:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5344964#M598829</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-11-06T10:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5345226#M598844</link>
      <description>&lt;P&gt;Hi Aref,&lt;BR /&gt;Thanks for your reply. Yes, I've tried delete authentication status condition from authorization rule, and it still the same.&amp;nbsp;&lt;BR /&gt;And I also following your documentation before, basically what I do just match the CN against Entra External Group.&lt;BR /&gt;And the results just like you've seen in the picture attached.&lt;BR /&gt;I've check and make sure from the Entra config, and all according to documentation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 05:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5345226#M598844</guid>
      <dc:creator>andrianusfranky</dc:creator>
      <dc:date>2025-11-07T05:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5345915#M598873</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SPAN class="UserName lia-user-name lia-user-rank-Level-1 lia-component-message-view-widget-author-username"&gt;&lt;A id="link_24" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1695295" target="_self" aria-label="View Profile of andrianusfranky"&gt;&lt;SPAN class=""&gt;andrianusfranky,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Level-1 lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp; I have the same problem. Did you get your issue fixed and may be share how it is fixed ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Nov 2025 17:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5345915#M598873</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-10T17:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5347217#M598969</link>
      <description>&lt;P&gt;I'm having the same problem. It seems the authentication flow between ISE and Entra ID isn't working. No matter what permission settings you configure; does anyone have a solution or fix for this?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 17:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5347217#M598969</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-11-14T17:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5347221#M598970</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1853632"&gt;@Andre-Teixeira&lt;/a&gt;&amp;nbsp;Hello at which section of the policy it is blocking&amp;nbsp; ? Is it at the Authentication or for the Authorization&amp;nbsp; ? What error you see ? Share the error log / code.&lt;/P&gt;
&lt;P&gt;I assume you completed the Entra ID Integration with ISE as External Identity Sources. Did you Import the Device or User Group already ? Is your cert DN matches the regex entry ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No matter what permission settings you configure -- which permission you are referring ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Elaborate a bit more on your problem&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 17:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5347221#M598970</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-14T17:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349028#M599052</link>
      <description>&lt;P&gt;Hello! I followed this link/guide:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We checked all the permissions for the Entra ID, ISE policies, and nothing. The documentation advises disabling Microsoft MFA, otherwise it doesn't work. We did this and the error persists. The REST within ISE is communicating normally with the tenant and the Entra ID app registration. We checked everything related to certificates; we inserted the certificate within the Entra ID app registration, issued a new certificate and a new chain, and imported it into ISE. We don't believe the problem is with certificates, because if I try to authenticate using a local Active Directory, for example: some domain user, it works with a different authentication policy and a different authorization policy.&lt;/P&gt;
&lt;P&gt;Error code: 5400 Authentication failed&lt;BR /&gt;Failure Reason 12976 EAP-TTLS authentication failed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 13:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349028#M599052</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-11-21T13:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349046#M599056</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1695295"&gt;@andrianusfranky&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a similar problem and was able to fix it. I was about to make a post talking about my issue.&lt;/P&gt;
&lt;P&gt;I was able to authenticate but when trying to use groups as conditions no groups matched and the authz was getting the default.&lt;/P&gt;
&lt;P&gt;In my case the problem was with the attributes ISE use from Azure.&lt;/P&gt;
&lt;P&gt;My problem was with the "deviceEnrollmentLimit" attribute, if I configure ISE to use this attribute and make authz profiles using groups as conditions it never matched.&lt;/P&gt;
&lt;P&gt;Try to mess with the attributes, if you have "deviceEnrollmentLimit" added try to take it off from the attribute list and see if this fiz your problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the REST ID Store i went to "User Attributes" and removed the "deviceEnrollmentLimit":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mafra_1-1763734977523.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255678i38B13FC98555D16D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mafra_1-1763734977523.png" alt="Mafra_1-1763734977523.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Logs showing the error I got when attributes were fetched for the user:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mafra_2-1763735082962.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255679iDDC925F83AE27ACC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mafra_2-1763735082962.png" alt="Mafra_2-1763735082962.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 14:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349046#M599056</guid>
      <dc:creator>Mafra</dc:creator>
      <dc:date>2025-11-21T14:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349058#M599058</link>
      <description>&lt;P&gt;I did that and I'm still having the same problem. Could you please share your APP Registration permissions? All of them. Maybe that will help me. Thank you very much for the information shared so far.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 15:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349058#M599058</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-11-21T15:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349065#M599059</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1853632"&gt;@Andre-Teixeira&lt;/a&gt;&amp;nbsp;Quick question - do you have the Group.Memership read permission on Azure for the Entra ID App&amp;nbsp; ?&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;
&lt;H4 id="toc-hId-1333319566"&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635&lt;/A&gt;&lt;/H4&gt;
&lt;H4&gt;User Lookup API Permissions&lt;/H4&gt;
&lt;P&gt;To perform the User attribute and group membership lookups against EntraID, the following API Permissions must be granted in the Entra ID App Registration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;User.Read.All (Application)&lt;/LI&gt;
&lt;LI&gt;GroupMember.Read.All (Application)&lt;/LI&gt;
&lt;/UL&gt;
&lt;SPAN class="UserName lia-user-name lia-user-rank-Level-1 lia-component-message-view-widget-author-username"&gt;&lt;A id="link_24" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1853632" target="_self" aria-label="View Profile of Andre-Teixeira"&gt;&lt;SPAN class=""&gt;Andre-Teixeira&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Nov 2025 15:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349065#M599059</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-21T15:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349068#M599060</link>
      <description>&lt;P&gt;During REST ID Integration it only works with Client Secret - Cert Option is not available in ISE side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 15:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349068#M599060</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-21T15:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349103#M599062</link>
      <description>&lt;P&gt;Thank you very much, but no success. I'm still getting the error log from my first attach&amp;nbsp;&lt;A id="link_43" class="lia-link-navigation attachment-link" href="https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349046?attachment-id=238738" target="_blank"&gt;login_failure_log_ise_entra_ID.png.&lt;/A&gt;&lt;BR /&gt;The error "AADSTS50034"...&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 17:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349103#M599062</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-11-21T17:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349107#M599063</link>
      <description>&lt;P&gt;Did you enable the debug for "rest-id-store"?&lt;/P&gt;
&lt;P&gt;I think you will have a better ideia what the problem is if you enable it and check on the CLI while the client tries to authenticate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CLI command after enable the debug:&lt;/P&gt;
&lt;P&gt;show logging application ropc/rest-id-store.log&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 17:22:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349107#M599063</guid>
      <dc:creator>Mafra</dc:creator>
      <dc:date>2025-11-21T17:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349108#M599064</link>
      <description>&lt;P&gt;Yes, I did. Same error message. Which version of Cisco ISE are you using?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 17:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349108#M599064</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-11-21T17:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349121#M599065</link>
      <description>&lt;P&gt;ISE3.5&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 18:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349121#M599065</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-21T18:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349150#M599066</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1853632"&gt;@Andre-Teixeira&lt;/a&gt;&amp;nbsp;- What is your Microsoft Entra ID License Type p1 , p2&amp;nbsp; ? and what's the attribute you are using as part of Authz ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know you are facing issue AuthC. Can you also share the Cert Auth Profile settings&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 21:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5349150#M599066</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2025-11-21T21:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5353205#M599236</link>
      <description>&lt;P&gt;My friends, good news. I managed to get it working. I spent about a month and a half trying to get this working in the simplest way possible. I tested the versions:&lt;BR /&gt;ISE 3.3 (patch 3) - fail&lt;BR /&gt;ISE 3.3 (patch 4) - fail&lt;BR /&gt;ISE 3.3 (patch 7) - fail&lt;BR /&gt;ISE 3.4 (patch 1) - fail&lt;BR /&gt;ISE 3.4 (patch 3) - fail&lt;BR /&gt;ISE 3.4 (patch 4) - fail&lt;BR /&gt;ISE 3.5, which we are discussing in this forum, - fail&lt;/P&gt;
&lt;P&gt;However, it only worked on version 3.3 WITHOUT ANY PATCH. I didn't change any configurations at all, I just installed 3.3 and removed patch 8. I performed a new authentication and it worked.&lt;/P&gt;
&lt;P&gt;I have attached the main configurations I performed to get it working. Through this forum, there is the possibility of contacting Cisco informing them:&lt;/P&gt;
&lt;P&gt;We need it to work in the simplest way possible, just like in version 3.3 without a patch. But since ISE cannot be left without updates, it needs to work on later versions. From there, we can make more advanced configurations.&lt;BR /&gt;&lt;BR /&gt;Perhaps the fact that it happens in all the latest versions (3.3 P2+, 3.4, 3.5) and not in 3.3 Base indicates that Cisco has permanently changed the library (SDK) or logic of the Azure AD connector in modern versions, probably to accommodate new Microsoft security requirements or MDM features, but broke backward compatibility for those using pure ROPC (only user authentication without device validation).&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 14:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5353205#M599236</guid>
      <dc:creator>Andre-Teixeira</dc:creator>
      <dc:date>2025-12-08T14:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.5 Entra ID Authorization Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5376666#M600055</link>
      <description>&lt;P&gt;Are you using "ENTRA DEVICE ID" to identify the device?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your Regex is the problem and thats why you are not hitting you Authorization rule. Try to put * before and after Entra Device ID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;* regex for Entra Device ID *&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2026 10:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-5-entra-id-authorization-problem/m-p/5376666#M600055</guid>
      <dc:creator>besart-rexhepi</dc:creator>
      <dc:date>2026-03-15T10:02:37Z</dc:date>
    </item>
  </channel>
</rss>

