05-22-2024 07:42 AM - edited 05-22-2024 07:50 AM
Our organization has been using Cisco ISE for network access control and are encountering a situation that we are struggling determine the next and/or proper approach. I'll summarize in point form...
The issue here occurs as there are two device certificates the PKCS and the SCEP, one published to AD and one not. The computer will present the certificate with the newest creation date, if the SCEP cert is sent then it is not found in AD as it is not published there (and Binary compare is on)
We are trying to determine how to best proceed with this and what is the most correct / industry standard approach here.
05-22-2024 12:44 PM
Binary compare is where I would focus. Eventually I assume all devices will be registered in Entra ID and InTune only rendering binary compare useless correct?
05-22-2024 12:58 PM - edited 05-22-2024 12:59 PM
Yes, ultimately I presume that's where we will be, how long it will be to get there is an unknown at this time.
With you expertise, would you have a good response to those who may have concerns with potential reduced security due to turning off binary compare?
My perspective is while it may not be the exact cert that is presented, it still matches details to what is published to AD which I figure is still quite secure (Same CA, CN, Purposes).
05-22-2024 02:01 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide