cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4634
Views
5
Helpful
4
Replies

ISE to Intune MDM

craiglebutt
Level 4
Level 4

Trying to setup Intune with ISE,

Certs installed and have all usage enable just to test

Baltimore

FEF.msub05.manage.microsoft.com

DigiCert Global Root

DigiCert SHA2 Secure

Doesn't matter what combination I tick , just get 

MDM Server API error
Connection Failed to the MDM server: There is a problem with the server Certificates or ISE trust store.

 

Removed all the config and tried again, still got the same.

Ran a Wireshark but couldn't see where the fault is.

 

Any ideas?

2 Accepted Solutions

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

Try adding the certificate DigiCert Global Root G2 from https://www.digicert.com/kb/digicert-root-certificates.htm to the ISE Trusted Certificates.

Microsoft updated the GraphAPI service just before ISE 3.0 was released and you need that cert for connecting to Azure AD to use their GraphAPI.  Intune may use the same.

View solution in original post

Hi Thomas

 

I found that yesterday and tried it, didn't work.

 

But I uploaded the Cert, so just added the PEM file, now it works


Cheers

View solution in original post

4 Replies 4

craiglebutt
Level 4
Level 4
Looked at them before posting on forum.
2nd link
Seems to be one of the latest documents
Seems to be missing the part about exporting the cert from PAN, also the links
No certs under https://graph.windows.netand https://fef.msuc05.manage.microsoft.com/

Following Integrate Cisco ISE with Intune - Intune | Microsoft Docs as well

thomas
Cisco Employee
Cisco Employee

Try adding the certificate DigiCert Global Root G2 from https://www.digicert.com/kb/digicert-root-certificates.htm to the ISE Trusted Certificates.

Microsoft updated the GraphAPI service just before ISE 3.0 was released and you need that cert for connecting to Azure AD to use their GraphAPI.  Intune may use the same.

Hi Thomas

 

I found that yesterday and tried it, didn't work.

 

But I uploaded the Cert, so just added the PEM file, now it works


Cheers