cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
16644
Views
16
Helpful
19
Replies

Access Manager

rwiesmann
Level 10
Level 10

Does anyone already have Access Manager available under Organization > Early Access ?

https://documentation.meraki.com/Access_Manager/Access_Manager_Overview/Architecture_and_Example_Use_Cases

It is documented that it will be rolled out in phases and I am wondering if this phases already started...

Seams to me an interesting approach as there is no external radius needed anymore.

19 Replies 19

miyakovlev
Frequent Visitor
Frequent Visitor

Anyone made it work? I can't connect to wireless, in logs I see that Access Manager still see MFA as required even though I excluded it from Conditional access for whole app in Entra ID. There are no docs available about it, I would have to turn off MFA because that's a step down in security.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

If your authentication methods have been migrated to "Modern" (which you cannot stop), you cannot use username/password authentication. You can only use certificate authentication.

This is because the modern authentication method FORCES the use of MFA. It is not possible to create a conditional access policy to prevent it.

rhinkamper1
Community Member

I got a quote for Access Manager, and the pricing is ridiculous. The fact that I have to pay the amount of money they quoted me so I can securely do NAC on their hardware is ridiculous.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

When I priced it up, it was 1/2 to 1/4 of the total cost of running Cisco ISE in Azure. I was thinking it was very well priced ...

Why don't you do NAC with Microsoft NPS, built into Windows Server?

That is how I do it now, but would rather perform NAC and its management via the Meraki portal. It just seems more efficient and logical to be managed in a "networking portal", and I honestly loathe Microsoft NPS.

Cisco charging an arm and a leg for a glorified radius server that just checks the validity of a certificate and group membership to grant access is ridiculous.