Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I am looking for some documentation to configure TEAP for Entra Joined Device and Entra Joined User when user will be using Wireless.
Assume that there is no Wired Connection and user will be using TEAP using Wireless.
Then user booted the machine ho...
Hello Greg,
If I want to use below condition of cert like Common Name and OU what will be CAP Auth Profile config ? Specially Use Identity From Field in CAP ? I think I should only use Subject ? which will cover CN , OU.
@Greg Gibbs
Hello Greg,
@Greg Gibbs
If User Device is Entra Joined and Users are Entra Joined and AD Joined in other words Hybrid is this use case is tested with ISE ? Is there a reference document you can share ?
If users are Hybrid joined can we still do NAC ...
Hello Greg,
@Greg Gibbs
Refer to your KB https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/ta-p/4763635#toc-hId-2135119435 and section - "Entra Joined Device and AD User with TEAP(E...
Regards to lookup you suggested to look and related to lookup Following is the key to make note from your KB.
"For the User lookups, ISE only supports using the User Principal Name (UPN), as described in the above sections.For the Device lookups, ISE...
@ahollifield ok you are saying if required certs are installed and then being wired auto config enabled ( even supplicant settings is not accurate ) then it will not show the auth failed error from LAN Interfaces as I explained ?
Reason I ask is - I ...
@ahollifield Since It is a new deployment , Plan is , required LAN Settings ( Authentication TAB from LAN Adapter ) will be enabled for dot1x as part of the pre migration plan for dot1x but during this period before cert is installed users should fal...