cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1607
Views
1
Helpful
2
Replies

Remote Access VPN using Cisco ISE and Microsoft Authenticator

rtromans01
Level 1
Level 1

Hi all,

Currently we have Cisco FirePowers as our VPN connectors and using Anyconnect as out VPN client. 

We are using Microsoft NPS for Radius authentication with AD and Microsoft Authenticator for MFA.

We are looking to introduce the number challenge with MS Authenticator for MFA and as part of this change I would like to introduce Cisco ISE to replace the NPS element. We are currently running version 3.2 patch 3 in ISE and after upgrading I noticed an announcement about SAML integration. 

Does anyone know if what I'm trying to achieve is possible and if there are any documents out there that may help, or has anyone else managed to implement this....

Many thanks

Richard

2 Accepted Solutions

Accepted Solutions

M02@rt37
VIP
VIP

Hello @rtromans01,

You'll need to configure SAML integration between these components to achieve your goal.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

View solution in original post

Greg Gibbs
Cisco Employee
Cisco Employee

See Cisco VPN: FTD & Microsoft: MS AAD ISE AuthZ with Posture 

Your use case would be the same flow, just without the Posture.

View solution in original post

2 Replies 2

M02@rt37
VIP
VIP

Hello @rtromans01,

You'll need to configure SAML integration between these components to achieve your goal.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

Greg Gibbs
Cisco Employee
Cisco Employee

See Cisco VPN: FTD & Microsoft: MS AAD ISE AuthZ with Posture 

Your use case would be the same flow, just without the Posture.