Security

 View Only
last person joined: 15 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - Intune integration - problem to logon to login.microsoftonline.com

This thread has been viewed 13 times
  • 1.  Clearpass - Intune integration - problem to logon to login.microsoftonline.com

    Posted Feb 04, 2021 09:49 AM

    We used the setup as described in the integration guide "Microsoft Intune" V5 (sept 2020)  . We are using a proxy environment that does SSL interception and are not able to logon to "login.microsoftonline.com" .  On AAD, we don't see anything happening, not even in the "sign in" logging.

    Has anyone had similar problems? Is it required to disable ssl interception ? 

    The extension installs / starts without problem, but when it tries to connect to MS, it fails : 

    [2021-02-04T15:05:00.102] [INFO] Intune - Refreshing devices with updates after Thu Feb 04 2021 15:00:00 GMT+0100 (CET).
    [2021-02-04T15:05:00.102] [INFO] Intune - Getting devices to process...
    [2021-02-04T15:05:00.198] [ERROR] Intune - Error getting device list. Request failed with status code 500
    Folllowed by  : The SSL handshake could not be performed.



    ------------------------------
    Danny Bosman
    ------------------------------


  • 2.  RE: Clearpass - Intune integration - problem to logon to login.microsoftonline.com

    Posted Feb 04, 2021 03:07 PM
    Danny {great name btw}..... I've never come across any other customer that has reported an ssl-inspect related issue, that's not to say its not there. 

    Putting the extension into DEBUG mode, does it provide any extra insight to the login issue?

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 3.  RE: Clearpass - Intune integration - problem to logon to login.microsoftonline.com

    Posted Feb 05, 2021 04:38 AM

    Hi Danny,
    after some trial & error, we are able to connect to MS by setting "verifySSLCerts": false & bypassProxy": true . We'll do some more testing with this setup. 

    Thx a lot for support & the document you wrote ! 



    ------------------------------
    Danny Bosman
    ------------------------------