02-12-2020 01:33 AM
Hi team,
I just wanted to confirm if we can use Active Directory on Azure for users authentication with ISE.
Thanks in advance for your help.
Best regards,
Solved! Go to Solution.
02-12-2020 01:51 AM
- Yes as a couple of the info's below will confirm :
M.
11-10-2020 08:26 AM
Partner SEVT - Security last week updated this guidance, I believe, with arrival of ISE 3.0. Need to confirm tho myself.
02-12-2020 01:51 AM
- Yes as a couple of the info's below will confirm :
M.
02-12-2020 02:46 AM
Thanks Marce1000 .
02-13-2020 04:44 AM
Hi @marce1000
I'd double-check that, since ISE does not allow Azure AD to be added as an external identity source. Yes, ISE does have SAML integration with Azure AD - but that is quite different than offering MSChapv2 authentication for things like EAP-PEAP authentication. As far as I know, you can not use Azure AD for credential authentication for EAP-PEAP (even if you managed to get a Secure LDAP connection to Azure AD - the password challenge doesn't work over LDAP). You can however use it to perform Authorization (e.g. checking that user X is a member of AD Group).
11-10-2020 08:26 AM
Partner SEVT - Security last week updated this guidance, I believe, with arrival of ISE 3.0. Need to confirm tho myself.
03-17-2021 01:17 PM
netizenden, did you ever confirm if AD on Azure can be used for EAP authentication with ISE 3.0?
03-17-2021 06:56 PM
See a similar discussion here:
https://community.cisco.com/t5/network-access-control/ise-azure-ad/td-p/4150923
The short answer is that this can only be done directly via ROPC which is very bleeding-edge has its own caveats and limitations.
02-13-2020 01:57 PM
Any integration with Azure AD would be done via SAML IdP and ISE does not currently support using a SAML IdP for endpoint authentication. SAML IdP is only supported for authentication of the following portals:
Guest portal (sponsored and self-registered)
Sponsor portal
My Devices portal
Certificate Provisioning portal
See the ISE Admin Guide for more information.
Cheers,
Greg
11-16-2023 04:19 AM
Hi Greg Gibbs,
after almost 3 years later, is there any change in SAML IdP for endpoint authentication ?
11-16-2023 01:16 PM
@stayd... No. SAML is browser-based, so it would require some significant updates to existing EAP protocols or a new EAP protocol to provide this functionality. This is not an ISE limitation, but rather an industry-wide limitation.
See this blog discussion for current options with ISE and Entra ID.
Cisco ISE with Microsoft Active Directory, Azure AD, and Intune
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide