Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass AzureAD authorization

This thread has been viewed 8 times
  • 1.  Clearpass AzureAD authorization

    Posted Aug 15, 2019 04:29 AM

    How are you guys solving authentication and authorization when customers retire their local AD and going with AzureAD, but keeping a local CPPM server/farm?

     

    Legacy authentication (EAP-PEAP) I understand is "dead" when going all cloud, so EAP-TLS I take is the way to go.

    What would we authenticate against then, as in, what would accept or deny the certificate presented (CPPM yes, but source - just that certifcate is signed by a trusted CA?)?

     

    How about authorization? Device attributes are ok, same with compliance state and device owner for example, via intune extesion, but what about AAD group membership?

    Machine+User authentication is a challenge then as well, as a machine can be used by users which should have different access levels.

     

    Any thoughts, ideas, solutions?



  • 2.  RE: Clearpass AzureAD authorization

    EMPLOYEE
    Posted Aug 15, 2019 06:11 AM

    hi HRossvoll,

     

    I would start with this document here:

     

    https://community.arubanetworks.com/t5/Security/ClearPass-Configuration-Guide-Onboard-Cloud-Identity-Providers/td-p/301657

     

    I think it is going to explain exactly what you are looking for 



  • 3.  RE: Clearpass AzureAD authorization

    Posted Aug 15, 2019 06:16 AM

    I briefly looked trough this, but since it mentioned the CPPM Onboard module I assume it was tied in to that process only.

    As I'm looking to do this without using CPPM onboarding, but handle management via intune or airwatch for example.

     

    I'll dig in to the document more in depth and come back with questions if any :)



  • 4.  RE: Clearpass AzureAD authorization

    EMPLOYEE
    Posted Aug 15, 2019 06:35 AM

    sure, you can replace ClearPass onboarding with every other onboarding process you like. but the document explains the main concepts very well.