<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure AD authentication on Meraki WiFi in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518746#M307273</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Can you please tell if you came up with any solution ?&lt;/P&gt;&lt;P&gt;We too have Azure AD and planning NPS Radius in Azure&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 09:02:47 GMT</pubDate>
    <dc:creator>Kushan</dc:creator>
    <dc:date>2023-03-24T09:02:47Z</dc:date>
    <item>
      <title>Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518665#M307192</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We are working on moving away from our on-premises AD to Azure AD. Part of our current infrastructure is using RADIUS authentication on our WiFi network, linked to our AD.&lt;/P&gt;&lt;P&gt;Seeing as using Azure AD directly isn't an option yet for Meraki, have you guys come up with any solutions for this?&lt;/P&gt;&lt;P&gt;I've been reading some posts about using a splash page to authenticate against Azure AD, but nothing specific or with a detailed configuration guide.&lt;/P&gt;&lt;P&gt;We don't want to spin up a VM in Azure just for this. I'm guessing we are not only ones facing this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518665#M307192</guid>
      <dc:creator>kevinkarnebeek</dc:creator>
      <dc:date>2019-06-18T08:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518666#M307193</link>
      <description>&lt;P&gt;Hello &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/2889"&gt;@kevinkarnebeek&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;At the moment, Meraki does not have a direct integration with Azure AD. However, since Azure AD is cloud-based, you would need to set up some kind of VPN set up anyway (until a direct VPN with Azure can be established). &lt;/P&gt;&lt;P&gt;I would recommend checking up on the vMX feature of Meraki. Following KB gives you some details on the setup&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MX/Installation_Guides/vMX100_Setup_Guide_for_Microsoft_Azure" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MX/Installation_Guides/vMX100_Setup_Guide_for_Microsoft_Azure&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 15:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518666#M307193</guid>
      <dc:creator>rohitraj</dc:creator>
      <dc:date>2019-06-19T15:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518667#M307194</link>
      <description>&lt;P&gt;Hello &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/23262"&gt;@rohitraj&lt;/A&gt; I hope you're doing well. Is there any positive updates regarding the Azure AD authentication on Meraki WiFi?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Oct 2019 18:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518667#M307194</guid>
      <dc:creator>KJ12</dc:creator>
      <dc:date>2019-10-26T18:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518668#M307195</link>
      <description>&lt;P&gt;We too are looking for this since we are moving our devices to Azure AD only.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 23:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518668#M307195</guid>
      <dc:creator>nicholas1101</dc:creator>
      <dc:date>2020-02-06T23:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518669#M307196</link>
      <description>&lt;P&gt;I would not recommend using a splash portal (open ssid) for corporate users. We are looking into a solution with ipsk and Azure. I'll keep you up to date.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 08:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518669#M307196</guid>
      <dc:creator>jonas@complit.be</dc:creator>
      <dc:date>2020-02-09T08:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518670#M307197</link>
      <description>&lt;P&gt;following, we have the same question. We do not want separate vm's or servers, just Azure AD authentication on our Meraki equipment.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 09:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518670#M307197</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2020-02-10T09:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518671#M307198</link>
      <description>&lt;P&gt;This question gets asked a lot on the Cisco ISE Community pages too. The challenge is that Azure AD is not the same as Active Directory (obviously) and the interfaces into Azure AD don't lend themselves to every use case. ISE for example, offers SAML interface to *some* parts of ISE (like Sponsor Portal Login page, or MyDevices Portal page) - but you cannot use Azure AD for things like EAP-PEAP authentication. Why? Because ISE has no native integration for such an external identity source. The closest you can get to that (with ISE) is to use Secure LDAP. But that breaks the password challenge algorithms (MS-CHAPv2) that is commonly used in EAP-PEAP - it cannot work. But the sLDAP integration could be used for non Authentication purposes - e.g. checking for AD Group membership during an EAP-TLS (cert based) authentication.&lt;/P&gt;&lt;P&gt;This is a challenge for every vendor and I have yet to come across a AAA vendor who has solved this problem. Be careful when reading that a product "integrates with Azure AD" - it's often very specific use cases only.&lt;/P&gt;&lt;P&gt;The solution to all this is probably a new protocol that runs over TLS (https) directly into public cloud providers.  You might want to look at JumpCloud.com to see what they are currently up to.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 22:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518671#M307198</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-13T22:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518672#M307199</link>
      <description>&lt;P&gt;You can use FreeRADIUS to do PEAP auth of users against Azure AD.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 05:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518672#M307199</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2020-02-14T05:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518673#M307200</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/244"&gt;@martyn.rees&lt;/A&gt; - that's good to know. Do you have actual experience with this? I'd like to learn how this is done. Please post some more information - I have some identities in Azure and a small lab to test with. I am not too familiar with Free Radius - if you have some kind of base config, that would be handy. &lt;SPAN class="lia-unicode-emoji" title=":thinking_face:"&gt;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 03:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518673#M307200</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-15T03:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518674#M307201</link>
      <description>&lt;P&gt;Have it running in production, though it was a while ago that I set it up, and I stupidly didn't even document it for future self. When I get some time I'll see if I can cobble together some steps&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2020 21:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518674#M307201</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2020-02-16T21:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518675#M307202</link>
      <description>&lt;P&gt;Now that the Azure AD DS is out, has someone ventured to setup this with Azure AD DS?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 21:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518675#M307202</guid>
      <dc:creator>gsn</dc:creator>
      <dc:date>2020-04-30T21:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518676#M307203</link>
      <description>&lt;P&gt;Azure AD DS has been available for some time. The issue that everyone is having is how to tell our glorious RADIUS servers how to use Azure AD DS. Whether FreeRADIUS, Cisco ISE or Clearpass - they all have the same issue.&lt;/P&gt;&lt;P&gt;I was on an ISE update session the other day and it was mentioned that ISE has support for SAML integration with Azure AD DS. Of course this only helps us for https (portal based) services, but not at all for EAP-PEAP, etc. - without divulging too much on the ISE roadmap, I believe there may be some work under way to utilise this SAML mechanism for other authentication means.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 22:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518676#M307203</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-04-30T22:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518677#M307204</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/23262"&gt;@rohitraj&lt;/A&gt;  azure offers the idea of conditional access based on a compliant device. i'm hoping that Meraki will build in a compliant device check via intune nac.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/mem/intune/protect/network-access-control-integrate" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.microsoft.com/en-us/mem/intune/protect/network-access-control-integrate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and leverage an oauth token to connect to intune&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.citrix.com/en-us/netscaler-gateway/12/microsoft-intune-integration/configuring-network-access-control-device-check-for-netscaler-gateway-virtual-server-for-single-factor-authentication-deployment.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.citrix.com/en-us/netscaler-gateway/12/microsoft-intune-integration/configuring-network-access-control-device-check-for-netscaler-gateway-virtual-server-for-single-factor-authentication-deployment.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 02:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518677#M307204</guid>
      <dc:creator>George D</dc:creator>
      <dc:date>2020-08-14T02:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518678#M307205</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Most of the Cloud Identity providers are just providing simple Username/Password and maybe MFA and masquerading that as full identity management solution. With ZeroTrust, those solutions are missing key components like End-Point posture assessment. O365 offers Intune, but it’s very limited with Macs and has limited end-point capabilities. There are a number of 3rd party offers as well, but now you are operating multiple security policies.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt; &lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;We also have lots of clients moving to cloud, but most realize that moving AD is the last thing they want moved. It’s the security ‘Crown Jewels’ and loosing control of that to a cloud provider should be considered as a major potential issue.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Providing 802.1x for NAC from the cloud has many other issues, mostly manifesting with users not getting basic local lan access. 1x can be very chatty in a dynamic environment and any delay above 100ms will cause timeouts resulting with either default guest access for privileged users at best, or no access at all at worst. Both options are sub-optimal.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;This is a classic ‘Just because you can, doesn’t mean you should’&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt; &lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Buyer beware. Just saving $$ should not be the primary driver when it comes to moving identity completely to the cloud.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt; &lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Okta, ping, and the rest of the cloud IAM are nothing more than just a unified SSO middleman, with a pretty front end. Execs love it, cause it looks good, but many IT organizations are realizing that they are losing all control of the end-point, and with ZeroTrust, the endpoint is just as important in deciding the correct access policy.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt; &lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt; &lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Some interesting points of view&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;A href="https://www.reddit.com/r/networking/comments/dj49s7/cloud_only_identity_providers_getting_rid_of_all/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.reddit.com/r/networking/comments/dj49s7/cloud_only_identity_providers_getting_rid_of_all/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 21:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518678#M307205</guid>
      <dc:creator>Tadpole86</dc:creator>
      <dc:date>2020-08-20T21:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518679#M307206</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/2889"&gt;@kevinkarnebeek&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Did you find a solation to this?&lt;/P&gt;&lt;P&gt;We are looking to do the same&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 14:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518679#M307206</guid>
      <dc:creator>jpcaid</dc:creator>
      <dc:date>2020-10-07T14:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518680#M307207</link>
      <description>&lt;P&gt;Hello, did you have a chance to look into the config ? thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 15:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518680#M307207</guid>
      <dc:creator>gsn</dc:creator>
      <dc:date>2020-10-07T15:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518681#M307208</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/20425"&gt;@gsn&lt;/A&gt; &lt;/P&gt;&lt;P&gt;We dont have any networking setup in azure.&lt;/P&gt;&lt;P&gt;ideally would like to use something that doesn't involve doing adding more complexity &lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 10:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518681#M307208</guid>
      <dc:creator>jpcaid</dc:creator>
      <dc:date>2020-10-08T10:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518682#M307209</link>
      <description>&lt;P&gt;Meraki has implemented WPA2-Enterprise auth with GSuite/Google, why not implement the exact same integration for AzureAD? &lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_WPA2-Enterprise_with_Google_Auth" target="_blank" rel="nofollow noopener noreferrer"&gt;Configuring WPA2-Enterprise with Google Auth - Cisco Meraki&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518682#M307209</guid>
      <dc:creator>GoVanguard</dc:creator>
      <dc:date>2021-01-26T21:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518683#M307210</link>
      <description>&lt;P&gt;i've been waiting for integration that leverages intune device compliance checks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 22:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518683#M307210</guid>
      <dc:creator>George D</dc:creator>
      <dc:date>2021-01-26T22:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD authentication on Meraki WiFi</title>
      <link>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518684#M307211</link>
      <description>&lt;P&gt;Meraki has SSO SAML integration with Azure for dashboard access.   Its has splash page sign in with 'out of the box' support for google and facebook.  But somehow, even with a UI that supports potentially endless idp's, MS is not there.  There are no legitimate support docs to build your own splash page.  &lt;/P&gt;&lt;P&gt;There is no logical reason to exclude MS as an idp for wifi sign in.  The question has been posted since 2017.   There is no technical reason.   The conspiracist in me thinks meraki hates MS ?,  google is paying meraki to exclude it?  the original developer of the meraki authentication lost the source code?  There has to be hundreds of thousands of potential meraki customers that would benefit from this.   It make no sense.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-ad-authentication-on-meraki-wifi/m-p/5518684#M307211</guid>
      <dc:creator>danderson2</dc:creator>
      <dc:date>2021-01-28T16:45:19Z</dc:date>
    </item>
  </channel>
</rss>

