cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
608
Views
0
Helpful
2
Replies

User Azure Group Cisco ISE

jsalmond
Level 1
Level 1

Afternoon, 

Hoping someone can help, 

I am setting up a PoC for Intune and trying to integrate our Cisco ISE to perform EAP-TLS  user Authentication which is working. Now followed the artificial here to https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html to configure Authorization based on Azure group membership which we are having issues with. 

The REST ROPC is configured and connection test is successful and Azure groups are available.  However from the live logs external groups are not being detected. 

I can see that they are being queried jsalmond_0-1696428847405.png

And the current username is detected from the certificate jsalmond_1-1696428986251.png the CN matches the users User principal name. We are using vanity domain not the onmicrosoft.com but this matches the UPN and also the username suffix configured under the REST (ROPC) 

 

Regards

 

2 Replies 2

Greg Gibbs
Cisco Employee
Cisco Employee

The latest patch for 3.2 is patch 3, so it's not possible to be running 3.2 patch 7.

I tested a similar scenario (using 3.2 p2) in which the User's UPN is my on-prem domain instead of my .onmicrosoft.com domain and it worked as expected for matching the User's group membership queried via REST ID in the AuthZ Policy.

To be clear, this flow in ISE 3.2 uses REST ID, not ROPC. As such, the 'Username Suffix' configured in the REST ID Store is not relevant to this flow. In my configuration, that suffix uses my .onmicrosoft.com domain suffix but the flow still worked with my on-prem domain suffix.

If you are not seeing any attributes for 'ExternalGroups' in the Live Log details, you may need to verify the Microsoft Graph API permissions are configured correctly. You should see the Entra Group ID(s) in this field as per this example from my testing.

Screenshot 2023-10-06 at 3.38.41 pm.png

Hi @Greg Gibbs thank you for your reply applagies I have just double checked and our ISE is running 3.1 patch 7 not 3.2. I have a maintanence windows next week that I will upgrate to version 3.2 patch 2 and see if we get this to work.