cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5224
Views
5
Helpful
2
Replies

Microsoft Azure MFA with Cisco ISE

md09
Level 1
Level 1

Hi,

I currently use Anyconnect VPN to connect via our ASA's.  Auth is via ISE to our on prem AD and a cloud based RSA provider for 2FA.

As the company is moving to Office 365 replacing the costly 2FA service with, the already paid for, Azure MFA is desirable.

I can only see references to this set-up where an on premise Microsoft MFA server is installed or a Microsoft NPS server is used.

I'd ideally like ISE to talk directly to Azure MFA (in the cloud).  Is this possible?

 

Many thanks

 

Mark

 

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

The Azure AD in the cloud is not providing any regular means (e.g. RADIUS or LDAP) for ISE to integrate with, other than what you already outlined, and SAML. While SAML is not a possible means for ISE to authenticate RA-VPN sessions, we may integrate ASA with it to secure RA-VPN user sessions and then use ISE for authorization. See my response at Re: Clarification on SAML authenticatio... - Cisco Community

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

The Azure AD in the cloud is not providing any regular means (e.g. RADIUS or LDAP) for ISE to integrate with, other than what you already outlined, and SAML. While SAML is not a possible means for ISE to authenticate RA-VPN sessions, we may integrate ASA with it to secure RA-VPN user sessions and then use ISE for authorization. See my response at Re: Clarification on SAML authenticatio... - Cisco Community

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: