Security

last person joined: yesterday 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Intune Extension + Wired MAC not found.

Jump to Best Answer
  • 1.  CPPM Intune Extension + Wired MAC not found.

    Posted Jan 08, 2021 04:08 PM
    We have CPPM configured to perform compliance lookups with Microsoft Intune following the latest Integration Guide (2020-01).

    We have this working with wireless clients, however during our testing, we noticed wired clients would be shown as not enrolled. When searching logs and analyzing the endpoint database in ClearPass, we see that wired endpoints had no Intune attributes and were unable to authenticate as a result of our security policy.


    Intune Extension log in Aruba ClearPass when ClearPass attempts a sync:

    'The device "DESKTOP-9T9P8D0" (27f2f00a-9a83-43ed-0000-111111111111}​​​​​​​​ does not have a MAC Address. Unable to process it.'

    Intune Extension log in Aruba ClearPass when user tries to authenticate:

    'Intune - The endpoint with the MAC Address 00-19-0e-16-3a-80 does not have an "Intune ID".'


    • Screenshot of device hardware showing the device name, Intune Device ID and Ethernet MAC.  Again, this works with wireless clients.

      To be clear, we have tested a laptop with both wired and wireless NICs.  On the same machine, wireless works associated to an Aruba network.  Wired does not work, when performing dot1x against a Cisco switch.





    ------------------------------
    Victor Castro
    ------------------------------


  • 2.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 10, 2021 10:21 PM

    I think I've narrowed down the issue. 

    It looks like the Microsoft Graph REST API v1.0 only has the wiFiMacAddress defined, while the beta API has an ethernetMacAddress.  I suspect this is likely the issue. 

    v1.0 API: https://docs.microsoft.com/en-us/graph/api/resources/intune-devices-manageddevice?view=graph-rest-1.0
    Beta API: https://docs.microsoft.com/en-us/graph/api/resources/intune-devices-manageddevice?view=graph-rest-beta

    I've attempted to add the ethernetMacAddress to the intuneAttributes section of the Intune extension configuration in CPPM but that just returns the following error: 

    [2021-01-10T21:42:36.481] [ERROR] Intune - {"error":{"code":"BadRequest","message":"Parsing OData Select and Expand failed: Could not find a property named 'ethernetMacAddress' on type 'microsoft.graph.managedDevice'.","innerError":{"date":"2021-01-11T02:42:48","request-id

    Another change I made was to have the extension pull all items, not just updated ones, as a result I'm seeing my wired-only devices being pulled down, but not added to the endpoint database as a result of no MAC address being available:

    [2021-01-10T22:00:01.204] [WARN] Intune - The device "DESKTOP-D80VMRE" (4c40059c-9afa-43b5-831d-c39b8a4b7170} does not have a MAC Address. Unable to process it.

    [2021-01-10T22:00:01.204] [DEBUG] Intune - {"id":"xxxx-9afa-xxxx","wiFiMacAddress":"","deviceName":"DESKTOP-D80VMRE","model":"OptiPlex 9020","osVersion":"10.0.18363.1237","operatingSystem":"Windows","userId":"xxxx-d040-4694-9xxxx","managedDeviceOwnerType":"personal","enrolledDateTime":"2021-01-10T21:19:27Z","lastSyncDateTime":"2021-01-11T01:25:23Z","complianceState":"compliant","jailBroken":"Unknown","managementAgent":"mdm","easActivated":true,"easDeviceId":"fffffBC30","easActivationDateTime":"0001-01-01T00:00:00Z","azureADRegistered":true,"deviceEnrollmentType":"windowsAutoEnrollment","activationLockBypassCode":null,"emailAddress":"castrov@xyz.com","azureADDeviceId":"-444c-bfd1-x","deviceRegistrationState":"registered","deviceCategoryDisplayName":"Unknown","isSupervised":false,"exchangeLastSuccessfulSyncDateTime":"0001-01-01T00:00:00Z","exchangeAccessState":"none","exchangeAccessStateReason":"none","remoteAssistanceSessionUrl":null,"remoteAssistanceSessionErrorDetails":null,"isEncrypted":true,"userPrincipalName":"castrov@","manufacturer":"Dell Inc.","imei":"","complianceGracePeriodExpirationDateTime":"9999-12-31T23:59:59Z","serialNumber":"3kk2","phoneNumber":"","androidSecurityPatchLevel":"","userDisplayName":"Victor Castro","configurationManagerClientEnabledFeatures":null,"deviceHealthAttestationState":null,"subscriberCarrier":"","meid":"","totalStorageSpaceInBytes":500106788864,"freeStorageSpaceInBytes":432788209664,"managedDeviceName":"castro_Windows_1/10/2021_9:19 PM","partnerReportedThreatState":"unknown"}


    Clearly the device is enrolled and CPPM +MS Intune are talking, it's just that Intune isn't returning the ethernet MAC with the v1.0 Graph API.

    Any idea if we change change to the beta Graph API?

    Thanks,
    Victor



    ------------------------------
    Victor Castro
    ------------------------------



  • 3.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 11, 2021 04:10 AM
    Victor,

    Please open a TAC support case to discuss these findings. If this is an issue, it has to be documented and TAC may be able to test your suggestions.

    Once you opened the case, please share the case number in a personal message with me, so I can see if I can route this to the right people quickly.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 4.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 11, 2021 09:55 AM
    Thanks Herman, will do!

    ------------------------------
    Victor Castro
    ------------------------------



  • 5.  RE: CPPM Intune Extension + Wired MAC not found.
    Best Answer

    Posted Jan 11, 2021 10:42 AM
    Victor,

    I received a confirmation from the product team on what you have seen and at the moment, not getting the wired MAC of an Intune client should be considered a limitation with the v5 version of the extension. You can ask TAC to republish the v4 version based on different APIs that do include the wired MAC. If you have the time to wait, this is being worked at and possible solutions are explored to get this limitation resolved.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 6.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 11, 2021 10:54 AM
    Oh, I've got so many questions.. LOL... Seems like a fairly significant limitation!

    Thanks for looking into this Herman!  We'll revert to V4 and test, is there anyway to follow along with progress and get timelines for resolution?

    Thanks again,
    Victor

    ------------------------------
    Victor Castro
    ------------------------------



  • 7.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 13, 2021 03:39 PM
    Hi Herman,

    We have V4 configured and again wireless is working.  So far no luck with wired authentication, any chance you have some additional insight?  The DEBUG logs in V4 are less informational.

    Thanks,
    Victor

    ------------------------------
    Victor Castro
    ------------------------------



  • 8.  RE: CPPM Intune Extension + Wired MAC not found.

    Posted Jan 14, 2021 05:07 AM
    Hello Victor,

    No, I'm not in constant communication with engineering. The best is to leverage the open TAC case and ask them for status updates.

    TAC as well can assist you with interactive troubleshooting on the wired authentication not happening. You can ask them to schedule a remote session and work with them on it to take out the round-trip times of forum or mail communication.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------