cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4249
Views
0
Helpful
4
Replies

2FA for ISE Administration Access

We want to have two factor for ISE administration with authorization based on AD group membership. Is there any config guide available?

1 Accepted Solution

Accepted Solutions

You may still use Active Directory for the identity store however, due to the 2FA/MFA requirement, it will not be ISE that does the authentication with AD. Instead, ISE will do a RADIUS proxy to the 2FA/MFA vendor (Cisco Duo?) and they will perform the initial AD Authentication followed by the second factor push/token/whatever.

See https://cs.co/ise-guides > Cisco Duo Security for guides and videos.

image.png

View solution in original post

4 Replies 4

marce1000
Hall of Fame
Hall of Fame

 

 - Check this thread :

           https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3876233

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Does this means, if I'm having any external radius for authentication then can't have AD for authorization? 

You may still use Active Directory for the identity store however, due to the 2FA/MFA requirement, it will not be ISE that does the authentication with AD. Instead, ISE will do a RADIUS proxy to the 2FA/MFA vendor (Cisco Duo?) and they will perform the initial AD Authentication followed by the second factor push/token/whatever.

See https://cs.co/ise-guides > Cisco Duo Security for guides and videos.

image.png