Security

 View Only
last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Checking Intune User Principal Name exists within an AD Group

This thread has been viewed 14 times
  • 1.  Checking Intune User Principal Name exists within an AD Group

    Posted Oct 22, 2021 12:52 AM
    Hi.

    I am trying to work out if the following is possible and if so, how to achieve it.

    I want to authentication user devices using EAP-TLS. These devices will be in InTune, so I am going to set up the InTune extension. The devices will range from iOS, Mac and Windows, some domain bound and some not.

    I'm looking for a way to check the "Intune User Principal Name" against an AD Group when a device authenticates to the WiFi. Based on the AD Group membership I would then like to assign different roles, i.e. Finance go to VLAN 100 and HR to VLAN 101.

    Is this do able?


  • 2.  RE: Checking Intune User Principal Name exists within an AD Group

    EMPLOYEE
    Posted Oct 22, 2021 11:09 AM
    I think if you use the techniques shown in this video, you can query AD based on the UPN, if the Intune UPN matches the UPN (or other field) in your AD.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Checking Intune User Principal Name exists within an AD Group

    Posted Oct 24, 2021 03:57 PM
    Hi.

    Thanks for replying. I have previously seen your video, and it is very helpful. What I think I'm struggling to grasp is how to check the InTune UPN against AD, in particular AD groups membership, as the InTune UPN is stored in Endpoint and it would need to cross-check it AD.


  • 4.  RE: Checking Intune User Principal Name exists within an AD Group

    EMPLOYEE
    Posted Oct 25, 2021 06:34 AM
    What does the InTune UPN look like? And is (or in which field in AD is) it stored?

    This probably is trivial if ones sees it... hard to answer based on this limited information. Would reach out to Aruba Support or your Aruba partner.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------