cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
288
Views
0
Helpful
2
Replies

Multiple Group Policies for Anyconnect VPN user via SAML

macejko8
Level 1
Level 1

Hello,

Is it possible to apply multiple group policies to anyconnect user via SAML group claim? We have similar setup like this one:https://www.cisco.com/c/en/us/support/docs/security/secure-client-5/221173-configure-dynamic-group-policy-assignmen.html

but instead of Okta we are using Azure AD. I know that article is saying that this setup works only if a user is a member of only one group, but I would like to have users in multiple groups thus they would get multiple group policies assigned

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Your connection profile (aka tunnel-group) can use Azure AD (Entra ID) SAML-based authentication. Your authorization result can then dynamically reassign users to different group-policies depending on their group membership. If they belong to multiple groups, multiple of which are considered for assignment then it is a bit tricky. The logic uses an alphabetic first match in that case.

Actually if I have a user in multiple groups, user is not able to connect to the VPN at all and getting this error: "Login denied, unauthorized connection mechanism, contact your administrator"