Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass and Azure AD

This thread has been viewed 65 times
  • 1.  ClearPass and Azure AD

    Posted Jun 29, 2020 08:16 PM

    Hi,

     

    My customer is using CP for User authentication via EAP-TLS. Currently CP is checking username against local AD.

    Client is moving everything on the Azure AD via itune and now EAP-TLS on testing phase is not working as CP can't do computer lookup on Azure AD. 

    One of the options I have suggested to use the secure ldap over internet but customer would like to go away from ldap and would like to use new authentication method like OAuth 2.0 or simmiler. 

    I have serached the blog but most of them are for the Guest account not for the EAP-TLS and all the EAP-TLS users the lldap. 

     

    Do we have any documentation or method which I can use without secure ldap?

     

    Please help.

     

    Thank you,

    Nilay Vyas.



  • 2.  RE: ClearPass and Azure AD

    MVP EXPERT
    Posted Jun 29, 2020 09:16 PM

    Azure AD does not use LDAP. If your devices are managed by Intune, you can use the Intune integration for authorization.



  • 3.  RE: ClearPass and Azure AD

    Posted Jun 29, 2020 09:28 PM

    Do you have any documentation for EAP-TLS via itune integration?



  • 4.  RE: ClearPass and Azure AD

    MVP EXPERT
    Posted Jun 29, 2020 09:30 PM
    Issuing certificates to Intune managed devices has nothing to do with CPPM. Take a look at the Microsoft docs.

    The Intune integration with CPPM is for authorization.


  • 5.  RE: ClearPass and Azure AD

    Posted Jun 29, 2020 10:08 PM

    Certficate is not an issues at all. .it is right now working with certificate only.. but I have disable the authorisation which pick up the CN name of the certificate and check against AD Fedration on site via ldap. Now as AD is on the Azure I can't check Autorisation lookup via ldap and client dose not want to use secure ldap. I am not sure how to get this working agin. If you have any documentation please point me to the link. 



  • 6.  RE: ClearPass and Azure AD

    MVP EXPERT
    Posted Jun 29, 2020 10:10 PM
    Are the devices under management by Intune?


  • 7.  RE: ClearPass and Azure AD

    Posted Jun 29, 2020 10:11 PM

    yes they are.. 



  • 8.  RE: ClearPass and Azure AD
    Best Answer

    MVP EXPERT
    Posted Jun 29, 2020 10:13 PM
    Then you can set up the Intune integration (arubanetworks.com/clearpassdocs) and leverage some of that data in your enforcement policies.


  • 9.  RE: ClearPass and Azure AD

    Posted Jun 29, 2020 10:20 PM

    Pleae correct me I am wrong but it means.. I configure the integration.. 

    keep EAP-TLS authorisation disable

    enable the autorisation in the policy and check agains the integration data being pulled out from itune and cached into the clear pass?

    so now the client require valid cerficiate + one or two of the autorisation policy I use to match aginst intue data?

     

    am I right?



  • 10.  RE: ClearPass and Azure AD
    Best Answer

    MVP EXPERT
    Posted Jun 29, 2020 10:26 PM
    yes


  • 11.  RE: ClearPass and Azure AD
    Best Answer

    EMPLOYEE
    Posted Jun 30, 2020 04:37 AM

    Please check the ClearPass with Azure integration videos on the Airheads Broadcasting Channel on Youtube.

     

    You can start with ClearPass integration with Intune and Azure AD - Part 1.1, and from there follow the other videos on this topic.



  • 12.  RE: ClearPass and Azure AD

    Posted Jul 06, 2020 07:38 PM

    Hi,

    Any one know what is the Firewall Ports requires to open in order to complete this integration. 

    Currently clearpass has no interent access. 

     

    Thank you. 



  • 13.  RE: ClearPass and Azure AD

    MVP EXPERT
    Posted Jul 06, 2020 07:39 PM

    The Intune integration requires access to the Intune API endpoints over TCP 443. 



  • 14.  RE: ClearPass and Azure AD

    Posted Jul 06, 2020 07:40 PM

    so that is Microsoft Office 365 URL. domina based firewall ruls am I right?



  • 15.  RE: ClearPass and Azure AD
    Best Answer

    MVP EXPERT
    Posted Jul 06, 2020 07:42 PM
    You should just allow HTTPS outbound for CPPM. It is required other things such as software updates anyway.