cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
630
Views
0
Helpful
1
Replies

Azure MFA + Cisco ISE integration

Hi,

I want to harden anyconnect vpn connection authentication.
At the moment I have configured the asa so that authentication works via certificate and login with active directory.
I was looking for the best way to integrate MFA.
I saw that it is also possible to do this with Azure MFA, only I wanted to understand if it is also possible to check the client's certificate, perhaps using the cisco ise.
Anyone have any suggestions?

 

Thanks in advance

1 Reply 1

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @danielesquaranti,

Currently, it is not supported to use SAML and certificate at the same time. Client certificate is requested by ASA, not ISE, in the authentication process on VPN.

You could enforce additional conditions in the Conditional Access Policy on Azure side, and to ask for 'Managed Device' condition to be satisfied too. This is also checking of certificate on your machine, just different one (they will be Azure issued certificates, issued upon Azure enroll process).

BR,

Milos