cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2952
Views
5
Helpful
3
Replies

ISE Admin Login 2FA

Steven Williams
Level 4
Level 4

Can you enable DUO auth within a policy for ISE admin login on the landing ISE page?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Yes, this should work.

Administrative Access to Cisco ISE Using an External Identity Store says, 

...

  • External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.

...

...

 

As DUO is a RADIUS token ID source similar to RSA SecurID, we would follow the same mode and need creating internal admin users with the same usernames as those on DUO.

 

View solution in original post

3 Replies 3

thomas
Cisco Employee
Cisco Employee

Please do Search the community for existing answers before posting questions.

Very unhelpful answer given that both of the links address something different than what he asked for.
If this posts answers your question or is helpful, please consider rating it and/or marking as answered.

hslai
Cisco Employee
Cisco Employee

Yes, this should work.

Administrative Access to Cisco ISE Using an External Identity Store says, 

...

  • External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.

...

...

 

As DUO is a RADIUS token ID source similar to RSA SecurID, we would follow the same mode and need creating internal admin users with the same usernames as those on DUO.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: