cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
520
Views
0
Helpful
1
Replies

SAML for Authentication with AD for Authorization - Cisco FMC 7.1

david.paganini
Level 1
Level 1

I have configured authentication for the VPN client (AnyConnect) using SAML. It's working with Azure.

 

When I use only authentication it works correctly, but if I enable authorization, using AD (I have realm configured) doesn't work.

 

Does anyone know how to enable authentication (SAML) in conjunction with authorization (AD - Realm)?

 

I'm using FMC 7.1 and AnyConnect 4.10.05.

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

What sort of Authorization results are you trying to configure?

Basic authorization like assignment of users to a group-policy can be done directly via AD using an LDAP attribute-map.

We usually use a RADIUS server (ISE or Microsoft NPS) for more advanced use cases.