Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

deploying via Mdm

This thread has been viewed 0 times
  • 1.  deploying via Mdm

    Posted Aug 22, 2019 08:21 PM

    Hey Gang,

     

    Im new to clearpass and have been setting up different ways of onboarding.
    none of the ways i have found can be deployed via Mdm ... at least the from my knowledge of all the components. does anyone have an article that can walk me through how to setup an onboard profile that will allow mdm onboard devices without the user having to do any type of intervention?

    i tried using the anonymous user option but that doesnt move from machint to machine easily (again, unless im missing how to do it)
    but it would be nice to have simplemdm add a machine based identifier in the profile and then enroll it

     

     



  • 2.  RE: deploying via Mdm

    EMPLOYEE
    Posted Aug 22, 2019 08:31 PM
    Does your EMM solution support SCEP or EST?


  • 3.  RE: deploying via Mdm

    Posted Aug 22, 2019 08:46 PM

    Not that im aware of



  • 4.  RE: deploying via Mdm

    EMPLOYEE
    Posted Aug 22, 2019 11:08 PM

    You'll need one of the two to automatically enroll a device certificate. Most major EMMs support at least one of them.



  • 5.  RE: deploying via Mdm

    Posted Aug 22, 2019 11:35 PM

    Fair, is there a resource on how to configure this if i was able to get an EMM?



  • 6.  RE: deploying via Mdm

    EMPLOYEE
    Posted Aug 23, 2019 08:33 AM

    It's usually documented by the EMM provider.



  • 7.  RE: deploying via Mdm

    Posted Aug 23, 2019 01:47 PM

    Forgive me, im not super familiar with EMM. 
    I know Slack has EMM that works with simpleMDM, would those two combined, be what i would be looking for in this context?



  • 8.  RE: deploying via Mdm

    EMPLOYEE
    Posted Aug 25, 2019 07:52 PM

    As far as I know, Slack does not have EMM capabilities built in, outside of basic app control. I have not heard of SimpleMDM, but you can reach out to them and see if they support certificate enrollment via SCEP or EST.