Wireless Access

 View Only
  • 1.  Client Tags - wireless access

    Posted Mar 04, 2025 06:58 AM
      |   view attached

    HI all !
    Trying to restrict only managed devices (Laptops) to access the wireless network.

    Currently i have successfully configured Okta integration, users can connect via Aruba Networking Onboarding, they manage to connect to the SSID and everything works.
    BUT that means that they connect with any device they want, mobile, personal laptop, work laptop etc.

    I understand there is a way to configure the devices that log in with user tags via client profile, and with the conditions there, to configure it to restrict access only to devices under the domain.

    the documentation is verry little (aruba guide), and there is know examples or explanation on how to configure the conditions.

    Any guide/help ?

    Thanks a lot !



  • 2.  RE: Client Tags - wireless access

    Posted Mar 04, 2025 07:37 AM

    With Client Tags you can do some AuthZ based on behavior and device information. Currently, Client Insight (CI) doesn't support integration with external authorization sources. 

    One of the conditions in the Tags is the Host Name. If the hostname contains a domein name this can maybe used. There is currently no build in option to restrict non-corp devices to join the network.

    One other option you can look into is the restriction of the device enrollment via the Onboard workflow.  During onboarding the user needs to login via an IdP. Maybe the Onboard application login can be restricted to corp only devices in Entra (or other IdP)?



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 3.  RE: Client Tags - wireless access

    Posted Mar 07, 2025 03:57 AM

    We're facing this exact same situation, except for iOS devices managed by Intune. The documentation on client tags and conditions is virtually non-existent. If I could find a way to tag a client device based on its Intune enrollment status, we'd be golden.




  • 4.  RE: Client Tags - wireless access

    Posted Mar 07, 2025 03:59 AM

    I've seen a demo on New Central where an integration with Intune does exactly that; so that may become available in the future. You could check with your local HPE Aruba team if I've seen/understood this correctly.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------