Security

last person joined: 8 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba ClearPass --- Intune MDM-- remote-wipe/lock

This thread has been viewed 3 times
  • 1.  Aruba ClearPass --- Intune MDM-- remote-wipe/lock

    Posted Jul 28, 2020 07:36 AM
      |   view attached

    Dear Airhead Community,

     

    I am trying to find out if devices, registred in Microsoft Intune, can be remotely locked or wiped within the ClearPass interface. no more, no less. According to the documentation of the newest ClearPass Intune integration Extension, V4.0 (as in the attachment below) and the CPPM 6.9 Guide i just can't find any information about the possibility to remote wipe/lock these devices. 

     

    Hopefully you guys can help me out.

     

    Yours faithfully,

     

    Roy Kleijnen



  • 2.  RE: Aruba ClearPass --- Intune MDM-- remote-wipe/lock
    Best Answer

    Posted Jul 28, 2020 09:51 PM

    Hi Roy,

     

    Yes and No. Let me explain.

     

    Today we use an API to talk to Azure/InTune we refer to as the NAC API V1.2, this API is what we've used for the past 4+ years. Under this API the more advanced and traditional features available from other UEM/MDM's such as Wipe/Lock is not available.

     

    Now to the better news, and great timing by the way.....last week we discussed a number of changes with M/Soft on a number of subjects and one of them was to move to using whats commonly called the GraphAPI, this provides for a vast number of new features which will include remote Lock / Wipe.

     

    Spoiler
    Now your next question is when.....email me at jump@hpe.com for an offline discussion.


  • 3.  RE: Aruba ClearPass --- Intune MDM-- remote-wipe/lock

    Posted Aug 14, 2020 02:09 PM

    So if someone were to be about to set this up and turn it on the old way, would you recommend holding on until this is going or go ahead and make it work and then update it later?  How bad is it going to be to reconfigure?