cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2111
Views
5
Helpful
3
Replies

ISE 3.1 integration with Azure Active Directory for VPN access

EDUARD LORENC
Level 1
Level 1

Can i get any reference documents or link to implement Two factor authentication for VPN users using ISE and external identity source Azure Active Directory?

1 Accepted Solution

Accepted Solutions

No, that option is not supported. See a similar discussion with additional links in this post...

Azure AD MFA for Anyconnect VPN clients with ISE 3.0 REST ID 

 

View solution in original post

3 Replies 3

Greg Gibbs
Cisco Employee
Cisco Employee

What are you using as the VPN headend? The smoothest way to do this is typically to use SAML for the MFA directly on the VPN headend (e.g. ASA or FTD) and use ISE on the backend for Authorize Only.

 

Yes, VPN headend is Cisco ASA. In our case ISE is used for Autentication and Authorization via configuration more then one external data sources. We would like to configure Authentication on ISE with external identity source Azure Active Directory. Could you send me link for configuration guide for direct ISE - AAD integration / extnernal identity source Autentication? Is this scenario supported?

 

No, that option is not supported. See a similar discussion with additional links in this post...

Azure AD MFA for Anyconnect VPN clients with ISE 3.0 REST ID