Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Intune Integration

This thread has been viewed 213 times
  • 1.  ClearPass Intune Integration

    Posted Feb 18, 2022 05:43 AM
    Hi All,

    We're getting lots of the following messages in the intune logs:

    [WARN] Intune - The device "deviceName" (AzureDeviceID} does not have a MAC Address. Unable to process it.

    The users device appears in the endpoint repo but with no Intune details.

    This doesn't occur for every user.  Any ideas?

    ------------------------------
    James Whitehead
    ------------------------------


  • 2.  RE: ClearPass Intune Integration

    Posted Feb 19, 2022 11:39 AM
    Make sure MAC Randomization is disabled.

    Also, we've had issues when the device was loaded into Intune from a different network adapter such as a wired docking station.


  • 3.  RE: ClearPass Intune Integration

    Posted Feb 23, 2022 01:08 PM
    Unless I'm mistaken this appears to be due to Intune not, since October, storing Android Wi-Fi MAC address details. I'm only seeing the issue on Android devices.

    Sauce: https://docs.microsoft.com/en-us/mem/intune/remote-actions/device-inventory
    NOTE: As of October 2021, Intune doesn't display Wi-Fi MAC addresses for newly enrolled personally-owned work profile devices and devices managed with device administrator running Android 9 and above.

    The ClearPass intune extension needs a MAC address of the intune device so it can store the devices' intune details in the endpoint repo.

    ------------------------------
    James Whitehead
    ------------------------------



  • 4.  RE: ClearPass Intune Integration

    Posted Feb 24, 2022 09:09 AM
    It would be nice if we could send the DeviceID from the certificate CN rather than the MAC address. 
    The extension looks up the device by the AzureID anyway, but references by MAC address. 

    Not sure if changing the filter query would work. 

    Upvote the Feature request, I've got plenty of use cases for this too. 
    https://innovate.arubanetworks.com/ideas/SEC-I-1781


  • 5.  RE: ClearPass Intune Integration

    Posted Feb 24, 2022 10:46 AM
    I thought that too and tried it out.

    [2022-02-24T15:39:37.396] [WARN] Intune - No endpoint with the MAC Address bdb303f7-a377-4d1e-99c9-76517775aea3 was found in ClearPass.
    
    Will upvote the feature request.

    ------------------------------
    James Whitehead
    ------------------------------