Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

social media login with office 365

This thread has been viewed 16 times
  • 1.  social media login with office 365

    Posted Dec 10, 2016 09:37 AM

    Does anyone know or have a manual on how to do this but with office 365?

    If i search in forum i find this but it just tell you how to do it with google and facebook but not with office 365

    http://community.arubanetworks.com/t5/Aruba-Solution-Exchange/ClearPass-Guest-Social-Logins/ta-p/218131

     

    Also if its possible to restrict  the login to one domain...  Let say i just want that people with @arubanetworks.com can log in using office 365. social media login.

     

    Cheers

    Carlos



  • 2.  RE: social media login with office 365

    Posted Dec 11, 2016 07:07 PM

    1. Browse to https://account.live.com/developers/applications, sign in with your Microsoft Live account, and click Add an App in the Live SDK Applications section.

    2016-12-11_16-22-56.png

    2. Enter an Application Name and click Create Application.

    2016-12-11_16-23-42.png

    3. On the Application Registration page, enter the FQDN of your ClearPass server into the Target Domain field. In the Redirect URIs field, enter the full URL of the ClearPass WebLogin page that you're using for social logins. There are some optional URLs that you can provide if you want to, along with a logo. Make note of the Application ID and Application Secret. You will use these values in the ClearPass configuration. Click Save when done.

    2016-12-11_16-36-05.png



  • 3.  RE: social media login with office 365

    Posted Dec 11, 2016 11:50 PM

    I cannot see the images :(

     

    Ill try that tomorrow

    Also do you know if its possible to use the social media login with office 365 but restrict it to one domain?

    I mean that just users with @alternetworks.net doamin can log in but someone else using office 365 with another doamin cannot use this

     

    Cheers

    Carlos



  • 4.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 12, 2016 06:00 AM
    So you're looking for a more corporate style login, right?

    You can use Azure AD instead which will limit it to your tenant.


  • 5.  RE: social media login with office 365

    Posted Dec 12, 2016 06:37 AM
    Can i use office365 credentials with that azure login?


  • 6.  RE: social media login with office 365

    Posted Dec 12, 2016 07:11 AM
    Also those users are not in the ad. Those are students that happen to have office 365 account but they do not have users in the ad as far i know


  • 7.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 12, 2016 07:15 AM
    Office 365 uses Azure AD as it's identity store. You'll have at least AAD Basic.


  • 8.  RE: social media login with office 365

    Posted Dec 12, 2016 07:20 AM
    Mmmm if its a different AD i guess. What i asked them if the student had a user in their local AD and the asnwer was no


  • 9.  RE: social media login with office 365

    Posted Dec 12, 2016 07:23 AM
    Does this azure login work on clearpass 6.5 or i need 6.6?


  • 10.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 20, 2016 09:43 PM

    Azure AD logins were added in ClearPass Guest 6.6.0



  • 11.  RE: social media login with office 365

    Posted Dec 21, 2016 07:27 AM

    I was reading a bit about this, i didt know that  Office 365 uses the cloud-based user authentication service Azure Active Directory to manage users until you mention it.

    So if i add this Azure AD ill be able to manage Office 365 users like AD and will be able even to create groups and give permitions to wifi to groups of users for example  Group A which contains student A, B, c has access and group B whichc contains Students D, E F does not have access, just like the AD but with office 365  users?

    It is like this? or im missunderstanding you Tim?



  • 12.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 21, 2016 07:31 AM
    Yes but keep in mind two things:

    1) Azure AD (or G Apps) cannot be used with PEAPv0/EAP-MSCHAPv2. You'd use this for Onboarding to EAP-TLS

    2) Account information is only checked during the initial authentication (Onboarding for example)


  • 13.  RE: social media login with office 365

    Posted Dec 21, 2016 07:36 AM

    If you at least can restrict the domain for example @alternetworkrs  that they just can log in that works for me.

    So you can defenitly do this right? just confirm me this and ill go and install a demo clearpass of 6.6 to try it.

    Sadly my demo clearpass i got in here it just 6.5 for the HD limitations guess i need to ask for a 1 TB HD to upgrade it to 6.6...



  • 14.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 21, 2016 07:41 AM
    Yes the Azure AD API client you create should be limited to the local tenant.


  • 15.  RE: social media login with office 365

    Posted Dec 21, 2016 07:43 AM

    Thaks tim ill try it.

    Do you know if there is any documentation of how to integrate this with azure AD with clearpass i can read?

     

    Cheers

    Carlos



  • 16.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 22, 2016 03:02 PM

    Hopefully, this link will point you in the right direction -

     

    http://community.arubanetworks.com/t5/Security/social-media-login-with-office-365/td-p/282775



  • 17.  RE: social media login with office 365

    EMPLOYEE
    Posted Dec 22, 2016 03:20 PM

    We don't have an Azure AD integration guide today. It's something we're working on.



  • 18.  RE: social media login with office 365

    Posted Dec 22, 2016 03:49 PM
    If there isnt a guide will tac hel us out to set it up?


  • 19.  RE: social media login with office 365

    Posted Jan 04, 2017 10:26 AM

    Hello Tim

    We need to configure this, and we have no idea how to configure it.  There is a client which wants this, and i cannot even do him a demo because there isnt any guide or something which tells you how to configure it

    Is there someone that could help me with this???

     

    Cheers

    Carlos



  • 20.  RE: social media login with office 365

    EMPLOYEE
    Posted Jan 09, 2017 08:56 PM

    Hi Carlos- 

     

    Happy to further assist you.  Mind sending me an email pegah.kamal@hpe.com with the details and best contact number / email?

     

    Cheers

     

    Pegah



  • 21.  RE: social media login with office 365

    Posted Jan 11, 2017 08:42 AM

    i already made it work im just stuck witht he mac caching on social media login hah



  • 22.  RE: social media login with office 365

    Posted Jan 11, 2017 09:10 AM
    Just need to add one of the Mac Auth expiry options define in the Time Source db using a post_auth enforcement profile (endpoint db update) when the user does the web-auth


    Get Outlook for iOS


  • 23.  RE: social media login with office 365

    Posted Jan 11, 2017 09:10 AM
    Just need to add one of the Mac Auth expiry options define in the Time Source db using a post_auth enforcement profile (endpoint db update) when the user does the web-auth


    Get Outlook for iOS


  • 24.  RE: social media login with office 365

    Posted Jan 11, 2017 09:33 AM
    Also on the Mac auth you either create a role mapping using the  (Authorization:[Time Source]:Now DT LESS_THAN %{Endpoint:MAC-Auth Expiry}) > [Mac Caching] - Tips Role

    Make sure that the endpoint db and time Source are used as a authorization
    Sources

    Get Outlook for iOS


  • 25.  RE: social media login with office 365

    Posted Jan 11, 2017 09:33 AM
    Also on the Mac auth you either create a role mapping using the  (Authorization:[Time Source]:Now DT LESS_THAN %{Endpoint:MAC-Auth Expiry}) > [Mac Caching] - Tips Role

    Make sure that the endpoint db and time Source are used as a authorization
    Sources

    Get Outlook for iOS