cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3622
Views
5
Helpful
6
Replies

Looking for a Cisco ISE configuration to work with Microsoft Intune

latenaite2011
Level 4
Level 4

Hey everyone,

 

Looking for a configuration guide or best practice setting for Cisco ISE policy to work with Microsoft Intune using EAP-TLS.

 

Thanks!

LN

2 Accepted Solutions

Accepted Solutions

marce1000
Hall of Fame
Hall of Fame

 

  - FYI : https://docs.microsoft.com/en-us/troubleshoot/mem/intune/integrate-cisco-ise-intune

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

craiglebutt
Level 4
Level 4

hi

 

Don't know why Microsoft can't make a API for it, specially as change are made.

Had to reconfigure this twice, these are the certs required

 

Baltimore CyberTrust Root,

Microsoft RSA TLS CA 01

DigiCert SHA2 Secure Server CA

DigiCert Global Root CA

 

Cheers, hope it helps

View solution in original post

6 Replies 6

marce1000
Hall of Fame
Hall of Fame

 

  - FYI : https://docs.microsoft.com/en-us/troubleshoot/mem/intune/integrate-cisco-ise-intune

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thanks Marce1000 for the reply.

Will this work with the Microsoft CA Server upgraded to SHA2?

craiglebutt
Level 4
Level 4

hi

 

Don't know why Microsoft can't make a API for it, specially as change are made.

Had to reconfigure this twice, these are the certs required

 

Baltimore CyberTrust Root,

Microsoft RSA TLS CA 01

DigiCert SHA2 Secure Server CA

DigiCert Global Root CA

 

Cheers, hope it helps

Criag:- Usually ISE needs trusting the root CA certificates only because the web servers of the API endpoints should send the full chains.

https://aka.ms/AzureCertUpdate has info on Azure TLS cert changes.

 

networks-at
Level 1
Level 1

Spent a good while importing certs into ISE and changing graph URL's only to find our ISE app in Azure needed AAD graph permissions (should have had by default apparently according to Azure support) as well as Microsoft Graph/Intune permissions that is in the documentation.