04-09-2024 06:25 PM
Hello
I have a couple of questions about ISE and Azure.
1.) What ISE external identity source integration works with Microsoft Azure so I can authenticate endpoints / computers that use Azure AutoPilot
2. How do I automatically get certificates on thousands of computers that are not members of a domain? (GPO won't work here)
3. If I want ISE to perform machine and user authentication and authorization for computers and users that are not members of AD domain, but are using Azure autopilot, how can I achieve that?
Thanks
Solved! Go to Solution.
04-09-2024 06:49 PM
The current available options for Authentication and/or Authorisation of Users/Devices against Entra ID are discussed in this post:
https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635
Certificates for Entra Joined endpoints would need to be enrolled using Intune. This would happen as part of the Autopilot process and ISE would have no control over this process.
04-09-2024 06:49 PM
The current available options for Authentication and/or Authorisation of Users/Devices against Entra ID are discussed in this post:
https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-azure-ad-and-intune/ta-p/4763635
Certificates for Entra Joined endpoints would need to be enrolled using Intune. This would happen as part of the Autopilot process and ISE would have no control over this process.
04-12-2024 11:27 AM
Thanks Greg,
The link was very helpful. What is the acceptable latency for radius authentication from the endpoints connected network access devices to ISE when hosted in Azure?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide