01-26-2026 07:42 AM
Hi,
I would like to authenticate:
external suppliers
connecting via Cisco Secure Client (AnyConnect)
authenticating against Entra ID
using Access Manager as the NAC solution
In short, the idea is the following:
using the existing AnyConnect client, users connect to the vMX, and through Access Manager policies, the authentication request is forwarded to Entra ID.
Is this scenario supported and technically feasible?
M.
01-26-2026 08:25 AM
It cannot receive a SAML request from the MX and forward it to Entra ID. Access Manager is not designed to authenticate VPN connections Its purpose is enforcing identity-based rules for network edges (switch/AP), not VPN hubs.
01-26-2026 10:43 AM
Also note that typically, you can only authenticate "member" users in your Entra ID.
You can authenticate Secure Client users directly against Entra ID (Access Manager is not required).
01-27-2026 12:04 AM
Hi Philip,
since i have few type of suppliers, can i give different group-policies? and where can i configure the group policies? cause in the MX there is only one group-policy to configure under the client-VPN-anyconnect section.
Thanks in adavance to both of you.
01-27-2026 01:01 PM
I don't know if it is documented anywhere, but I explain how to apply per group policies here.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide