09-24-2020 05:17 AM
We want to have two factor for ISE administration with authorization based on AD group membership. Is there any config guide available?
Solved! Go to Solution.
09-24-2020 11:34 AM
You may still use Active Directory for the identity store however, due to the 2FA/MFA requirement, it will not be ISE that does the authentication with AD. Instead, ISE will do a RADIUS proxy to the 2FA/MFA vendor (Cisco Duo?) and they will perform the initial AD Authentication followed by the second factor push/token/whatever.
See https://cs.co/ise-guides > Cisco Duo Security for guides and videos.
09-24-2020 05:23 AM
- Check this thread :
https://community.cisco.com/t5/network-access-control/ise-admin-login-2fa/m-p/3876233
M.
09-24-2020 08:17 AM
Does this means, if I'm having any external radius for authentication then can't have AD for authorization?
09-24-2020 11:34 AM
You may still use Active Directory for the identity store however, due to the 2FA/MFA requirement, it will not be ISE that does the authentication with AD. Instead, ISE will do a RADIUS proxy to the 2FA/MFA vendor (Cisco Duo?) and they will perform the initial AD Authentication followed by the second factor push/token/whatever.
See https://cs.co/ise-guides > Cisco Duo Security for guides and videos.
09-24-2020 05:32 AM
how about below guide :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide