- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2023 04:31 AM
Hi all,
Currently we have Cisco FirePowers as our VPN connectors and using Anyconnect as out VPN client.
We are using Microsoft NPS for Radius authentication with AD and Microsoft Authenticator for MFA.
We are looking to introduce the number challenge with MS Authenticator for MFA and as part of this change I would like to introduce Cisco ISE to replace the NPS element. We are currently running version 3.2 patch 3 in ISE and after upgrading I noticed an announcement about SAML integration.
Does anyone know if what I'm trying to achieve is possible and if there are any documents out there that may help, or has anyone else managed to implement this....
Many thanks
Richard
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2023 05:14 AM
Hello @rtromans01,
You'll need to configure SAML integration between these components to achieve your goal.
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2023 03:38 PM
See Cisco VPN: FTD & Microsoft: MS AAD ISE AuthZ with Posture
Your use case would be the same flow, just without the Posture.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2023 05:14 AM
Hello @rtromans01,
You'll need to configure SAML integration between these components to achieve your goal.
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2023 03:38 PM
See Cisco VPN: FTD & Microsoft: MS AAD ISE AuthZ with Posture
Your use case would be the same flow, just without the Posture.
