06-10-2024 02:10 AM
Hello!
Our management wants to implement a Microsoft Authenticator based second factor to our ISE vpn.
Now we are using the ISE (FTD) vpn with only on-prem AD auth, and my question is how can we implement this Microsoft (Azure) Authenticator?
Is there a guide somewhere?
Thanks!
06-10-2024 11:08 AM
SAML to Entra ID/MS? ISE as authorize-only? Or use SAML assertion from Entra and not use ISE at all here.
06-11-2024 12:39 AM
I think I dont understand your suggestions. We should use Entra ID as auth source instead of on-prem AD?
And what is SAML assertion from Entra ID? In this case what will ISE do?
06-11-2024 02:16 AM
06-11-2024 04:10 AM
It sounds like an on-prem AD replacement, but what we need is a Second Factor, like a push notification or an OTP message during tha authentication. The AD would be the 1st and the Microsoft Authtenticator method the 2nd factor.
I dont see this in your suggestion.
06-11-2024 04:29 AM
06-11-2024 07:58 AM - edited 06-11-2024 07:59 AM
Like Adam is saying, directly to Entra ID via SAML with MFA setup there is the cleanest authentication with MFA experience. ISE can then do Authorization and Accounting.
If you use on-premise AD with sync to Entra ID and want to continue with that (no immediate good reason why comes to mind) then you can do authentication to NPS with cloud connector, either directly from FTD or via ISE with NPS as an external RADIUS server in that case. Those are all a lot more fragile and more difficult to troubleshoot.
06-12-2024 05:37 AM
Okay. In that case the Authentication part must be configured on the Headend (Firepower), right?
The ISE config would not be changed at all?
06-12-2024 09:24 AM
Depends, do you want to? Are you using Posture? Have any other use-cases?
06-13-2024 04:27 AM
This sounds promising for us! If we want to use Entra ID as Authentication source, and then ISE as Authorization, how would the flow look like?
Tha Etra ID is configured on the Firepower Headend and after successful auth the authorization would be handled by the ISE?
How?
Thank
06-13-2024 04:37 AM
06-13-2024 04:50 AM
But in the ISE Policy what would be the auth source in that case?
Because it is handled by the Firepower.
06-13-2024 04:59 AM
06-14-2024 12:15 AM
Thank you! It is working!
Tho no configuration change was need on the ISE side, it could handle the only-authorization sessions by default.
Just the Firepower config change was required.
THX
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide