10-04-2023 07:23 AM - edited 10-06-2023 01:25 AM
Afternoon,
Hoping someone can help,
I am setting up a PoC for Intune and trying to integrate our Cisco ISE to perform EAP-TLS user Authentication which is working. Now followed the artificial here to https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/218197-configure-ise-3-2-eap-tls-with-azure-act.html to configure Authorization based on Azure group membership which we are having issues with.
The REST ROPC is configured and connection test is successful and Azure groups are available. However from the live logs external groups are not being detected.
I can see that they are being queried
And the current username is detected from the certificate the CN matches the users User principal name. We are using vanity domain not the onmicrosoft.com but this matches the UPN and also the username suffix configured under the REST (ROPC)
Regards
10-05-2023 09:43 PM - edited 10-05-2023 09:43 PM
The latest patch for 3.2 is patch 3, so it's not possible to be running 3.2 patch 7.
I tested a similar scenario (using 3.2 p2) in which the User's UPN is my on-prem domain instead of my .onmicrosoft.com domain and it worked as expected for matching the User's group membership queried via REST ID in the AuthZ Policy.
To be clear, this flow in ISE 3.2 uses REST ID, not ROPC. As such, the 'Username Suffix' configured in the REST ID Store is not relevant to this flow. In my configuration, that suffix uses my .onmicrosoft.com domain suffix but the flow still worked with my on-prem domain suffix.
If you are not seeing any attributes for 'ExternalGroups' in the Live Log details, you may need to verify the Microsoft Graph API permissions are configured correctly. You should see the Entra Group ID(s) in this field as per this example from my testing.
10-06-2023 01:26 AM
Hi @Greg Gibbs thank you for your reply applagies I have just double checked and our ISE is running 3.1 patch 7 not 3.2. I have a maintanence windows next week that I will upgrate to version 3.2 patch 2 and see if we get this to work.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide