08-17-2021 12:57 AM
Hi Guys,
is it possible, in your opinion,use azure AD to authenticate guest users (with portal?)
I would like to implement a guest wifi (open access) for internet access where:
- guest are sponsored
- employee use their azure credentials
In case can you provide some good links where i can find how to implement this solutions?
Regards
Solved! Go to Solution.
08-21-2021 05:59 PM
> only one captive portal must be used for employee with AZ-AD and guest with self-registration
Even so, we may create two portals and link one to the other to create Alternative Login Option.
You may follow Configure ISE 2.1 Guest Portal with PingFederate SAML SSO and replace PingFederate with AAD.
08-17-2021 02:06 AM
08-17-2021 04:26 AM
Hi Milos,
helpful link
i have to study thsi solution and check if it fits with my needs.
Thank you very much
08-18-2021 04:20 AM
##- Please type your reply above this line -##
08-18-2021 06:34 AM
Hi @Xeladona,
These are additional requirements then your intial ones
On Sponsor portal you can either choose SAML IDP or Identity Store Sequence (which can contain internal users and other external ID sources such as AD or LDAP). You can't mix these, so the answer would be no. You could create multiple Sponsor portals, if that suits you, and then to use SSO on one, and Identity Store Sequence on another.
I don't know much about Azure AD (apart from what I already used), but this request doesn't seem natural to me
BR,
Milos
08-18-2021 03:39 PM
This is more of a combination between true Guest and BYOD use cases. A better option, and one that worked well for a large enterprise, would be to use a separate BYOD SSID for your employees that authenticates against Azure AD. This SSID could be anchored out to the DMZ to provide basic internet access similar to the true Guest network.
08-19-2021 03:33 AM
Hi Greg,
first of all thank you for your kindly reply.
Your solution, even if valid, unluckly does not meet customer requirement (only one captive portal must be used for employee with AZ-AD and guest with self-registration).
So my only way is or to demonstrate it is impossible and propose other solution or find out a way to match his needs.
Best Regards
08-24-2021 05:40 AM
Hi Greg,
i have to investigate further about this solution but at first could be valid.
as far as very helpful i will keep ypu informed about the developments
Regards
08-21-2021 05:59 PM
> only one captive portal must be used for employee with AZ-AD and guest with self-registration
Even so, we may create two portals and link one to the other to create Alternative Login Option.
You may follow Configure ISE 2.1 Guest Portal with PingFederate SAML SSO and replace PingFederate with AAD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide