Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba Cloud Auth & Entra (Azure) Conditional Access

This thread has been viewed 13 times
  • 1.  Aruba Cloud Auth & Entra (Azure) Conditional Access

    Posted 9 days ago

    Hello. Can Entra Conditional Access be used to apply restrictions or limitations to Aruba Cloud Auth? Example scenario is to restrict SSO login to configured Aruba Cloud Auth when attempting to log in from a non company-managed device. Thanks.



  • 2.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    EMPLOYEE
    Posted 2 days ago

    While I have not tried, I would say that with Conditional Access you can restrict the onboarding process. After the onboarding, there  is no interaction with the SSO as a client certificate will be used for the actual network authentication. Removed/disabled users will be periodically verified against Entra ID to prevent further network access.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    Posted 2 days ago

    Thanks. Does HPE/Aruba have any guidance on what that conditional access policy might look like, or any similar scenarios/recommendations to that end?

     

    Thanks,

     

    Doug

     






  • 4.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    EMPLOYEE
    Posted 11 hours ago

    I have not seen such. Conditional Access is something in Entra ID, and Cloud Auth just consumes that as functionality.

    Also, a conditional access policy depends on your own policy/preference to allow or disallow users/devices access to onboarding their devices, and what access they would get after onboarding. A generic guidance would be to determine what access you would allow to onboarded devices. If that is full network access to the internal network, putting a restriction on non-corporate devices would make sense, if you allow internet only, putting a restriction on corporate devices may make sense as well, as the internet only access may bypass your corporate security products like firewalls, IDS, proxies, etc. It really depends.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    Posted 9 hours ago

    Thanks Herman, I appreciate that. Our team was able to create the appropriate policy in Azure/Entra ID which restricts Azure authentication from the Aruba/HPE SSO unless the device is a managed device. From a PC-perspective at least for the scope of our test.

     

    Thanks,

     

    Doug

     






  • 6.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    EMPLOYEE
    Posted 5 hours ago

    If you are able to share how this was done, it may help others. The question pops up every now and then, and at least now I have a confirmation it actually works, but still not how it should be done.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: Aruba Cloud Auth & Entra (Azure) Conditional Access

    Posted 4 hours ago

    Sure; I'll look to see how we did it and get back to you!

     

    Doug