cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
241
Views
0
Helpful
1
Replies

ISE 3.2 - Azure REST ID vs devices

Hi,

I have established connection between ISE 3.2 and Azure with REST ID. Users I can authenticate but I can't do the same for PCs. I know there is limitation:

 Note: ROPC is limited to User authentication since it relies on the Username attribute during authentication. Device objects in Azure AD do not have Username attributes.

But is there a way I can authenticate devices against Azure without MDM compliance? I can check PC's certificate only, but it is not what I want to have in the end.

Thank you for any suggestions.

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

No. There is no way to authenticate a 'Device' in Entra ID. See this blog discussion for more detail on why and the current available options.

https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635

 

View solution in original post

1 Reply 1

Greg Gibbs
Cisco Employee
Cisco Employee

No. There is no way to authenticate a 'Device' in Entra ID. See this blog discussion for more detail on why and the current available options.

https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635