Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Does ClearPass support Azure AD DC?

This thread has been viewed 8 times
  • 1.  Does ClearPass support Azure AD DC?

    Posted Oct 10, 2019 03:51 AM

    Hi, I have a client, which wants to use ClearPass, but he wants to use not on-premises ad dc, but azure ad dc.

    Maybe someone had this kind of case and can share your knowledge.

     

    ClearPass would be used  for Wifi users and LAN users EAP-TLS or EAP-PEAP authentication.



  • 2.  RE: Does ClearPass support Azure AD DC?



  • 3.  RE: Does ClearPass support Azure AD DC?

    Posted Oct 10, 2019 05:48 AM

    So to be clear, EAP-TLS is only possible solution.

     

    One more thing, how ClearPass check user name from certificate common name field? because when we used on-Premise CA and AD DC, ClearPass using EAP-TLS authentication always check does user exit in AD DC and CLearPass use received  user certificate common name field. So how  this time ClearPass would check user  over OAuth 2.0 ? Because I did not find straigh answer.



  • 4.  RE: Does ClearPass support Azure AD DC?

    EMPLOYEE
    Posted Oct 10, 2019 07:58 PM
    There is no user check after Onboarding.


  • 5.  RE: Does ClearPass support Azure AD DC?

    Posted Oct 11, 2019 02:22 AM
      |   view attached

    Yes there is user check, I am sending you my ClearPass authentication one recod  begining. After user check  certificate check is following, tell me my mistakes please. Common name field value is used from certificate as user  name to check. I am using EAP-TLS auth.



  • 6.  RE: Does ClearPass support Azure AD DC?

    EMPLOYEE
    Posted Oct 11, 2019 09:36 AM

    You need to disable authorization in the EAP-TLS configuration.



  • 7.  RE: Does ClearPass support Azure AD DC?

    Posted Oct 13, 2019 12:39 PM

    1. So the only possible check is certificate and  user check is not possible? Just say yes or no?

     

     

     

     



  • 8.  RE: Does ClearPass support Azure AD DC?

    EMPLOYEE
    Posted Oct 13, 2019 08:38 PM

    Yes, the credential is validated.