08-12-2021 07:54 PM
Hey everyone,
Looking for a configuration guide or best practice setting for Cisco ISE policy to work with Microsoft Intune using EAP-TLS.
Thanks!
LN
Solved! Go to Solution.
08-13-2021 01:35 AM
- FYI : https://docs.microsoft.com/en-us/troubleshoot/mem/intune/integrate-cisco-ise-intune
M.
08-13-2021 07:01 AM
hi
Don't know why Microsoft can't make a API for it, specially as change are made.
Had to reconfigure this twice, these are the certs required
Baltimore CyberTrust Root,
Microsoft RSA TLS CA 01
DigiCert SHA2 Secure Server CA
DigiCert Global Root CA
Cheers, hope it helps
08-13-2021 01:35 AM
- FYI : https://docs.microsoft.com/en-us/troubleshoot/mem/intune/integrate-cisco-ise-intune
M.
08-16-2021 03:58 PM
08-17-2021 10:32 PM
Also see How to: Integrate Cisco ISE MDM with Microsoft Intune (Cisco Community) by one of our TMEs.
08-13-2021 07:01 AM
hi
Don't know why Microsoft can't make a API for it, specially as change are made.
Had to reconfigure this twice, these are the certs required
Baltimore CyberTrust Root,
Microsoft RSA TLS CA 01
DigiCert SHA2 Secure Server CA
DigiCert Global Root CA
Cheers, hope it helps
08-14-2021 03:06 PM
Criag:- Usually ISE needs trusting the root CA certificates only because the web servers of the API endpoints should send the full chains.
https://aka.ms/AzureCertUpdate has info on Azure TLS cert changes.
08-24-2021 05:51 AM
Spent a good while importing certs into ISE and changing graph URL's only to find our ISE app in Azure needed AAD graph permissions (should have had by default apparently according to Azure support) as well as Microsoft Graph/Intune permissions that is in the documentation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide