Isn’t SAML entirely a web-based thing? Sure, you can tie it into the actual website URL of your ASA, but what about logging in directly from the AnyConnect client itself? This is not referenced in any documents I’ve seen so far. Is this possible?
website login for AnyConnect would be unfriendly to many users who are already hostile to having to use VPN in the first place. My research on the topic is that many people are going to ISE 3.0 and using PAP to go to Azure AD for RA AnyConnect. Additionally Azure AD doesn’t seem to support PEAP-MSCHAPv2 right now, which does directly concern wireless. (and yes I know EAP-TLS is the the way that it “should” be done, but the “should" doesn’t materialize into reality for many people. Many simply are not in a position to roll out EAP-TLS) Azure AD seems to be designed with Cloud web-apps in mind only, and this apparently is creating alot of gaps on the Networking end, and Microsoft is not in the Networking business to care. Please correct me on any point, I do have alot of knowledge gaps on this subject. - Matt On Aug 26, 2021, at 9:14 AM, Jeffrey D. Sessler <[email protected]<mailto:[email protected]>> wrote: WARNING: This email originated external to the NMSU email system. Do not click on links or open attachments unless you are sure the content is safe. I 2nd Tim’s suggestion. If the VPN is Cisco-based, they support using SAML against AzureAD including MFA. https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215935-configure-asa-anyconnect-vpn-with-micros.html Jeff From: The EDUCAUSE Wireless Issues Community Group Listserv <[email protected]<mailto:[email protected]>> on behalf of Manon Lessard <[email protected]<mailto:[email protected]>> Date: Thursday, August 26, 2021 at 7:54 AM To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: Re: [WIRELESS-LAN] ISE-NPS-Azure MFA We are talking VPN here and for the entire campus… Manon Lessard Chargée de programmation et d’analyse CCNP, CWNE #275, AWA 10, ESCE Design Direction des technologies de l'information Pavillon Louis-Jacques-Casault 1055, avenue du Séminaire Bureau 0403 Université Laval, Québec (Québec) G1V 0A6, Canada 418 656-2131, poste 412853 Télécopieur : 418 656-7305 [email protected]<mailto:[email protected]> www.dti.ulaval.ca<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.dti.ulaval.ca%2F&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252337862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=%2FfwassNcb%2F%2BSGKqQ82Se5KxpAUoBFPbPtZDbU7Uylm4%3D&reserved=0> Avis relatif à la confidentialité | Notice of Confidentiality<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.rec.ulaval.ca%2Flce%2Fsecurite%2Fconfidentialite.htm&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252347857%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=yi11CEEfHsdZlahlQGe89SW7lkOpikhLlSbTGS7%2BZQg%3D&reserved=0> From: The EDUCAUSE Wireless Issues Community Group Listserv <[email protected]<mailto:[email protected]>> on behalf of James Andrewartha <[email protected]<mailto:[email protected]>> Reply-To: The EDUCAUSE Wireless Issues Community Group Listserv <[email protected]<mailto:[email protected]>> Date: Thursday, August 26, 2021 at 10:50 AM To: "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: Re: [WIRELESS-LAN] ISE-NPS-Azure MFA Microsoft note this behaviour and have some sort of workaround in their NPS MFA extension: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension#radius-protocol-behavior-and-the-nps-extension<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-mfa-nps-extension%23radius-protocol-behavior-and-the-nps-extension&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252347857%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=ftbr5gySi10k6XMgZeL%2B48rmHs4dWCx4LAiv%2Bw%2BByUw%3D&reserved=0> Really though, doing MFA for RADIUS is a square peg in a round hole, use MFA to provision a client cert and do EAP-TLS instead. From: The EDUCAUSE Wireless Issues Community Group Listserv <[email protected]<mailto:[email protected]>> on behalf of Manon Lessard <[email protected]<mailto:[email protected]>> Reply to: The EDUCAUSE Wireless Issues Community Group Listserv <[email protected]<mailto:[email protected]>> Date: Thursday, 26 August 2021 at 10:20 pm To: "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: [WIRELESS-LAN] ISE-NPS-Azure MFA A question not directly related to Wi-Fi, but related to ISE which seems to be something some of you use. We are currently authenticating a VPN test group via ISE through NPS servers (defined as a token server). The goal is to do MFA with Azure through the Authenticator app on people’s phones. Everything works, but Authenticator pops up for confirmation, sometimes 2 to 3 times, even if one has accepted the first confirmation… I would like to have feedback from people who used something like that and have solved the multiple Authenticator prompts. Thank you Manon Lessard Chargée de programmation et d’analyse CCNP, CWNE #275, AWA 10, ESCE Design Direction des technologies de l'information Pavillon Louis-Jacques-Casault 1055, avenue du Séminaire Bureau 0403 Université Laval, Québec (Québec) G1V 0A6, Canada 418 656-2131, poste 412853 Télécopieur : 418 656-7305 [email protected]<mailto:[email protected]> www.dti.ulaval.ca<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.dti.ulaval.ca%2F&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252357849%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0VUJKjfPG2MwvHpbdjDbPOwYYly0PcbeI8AJm%2BKVmRs%3D&reserved=0> Avis relatif à la confidentialité | Notice of Confidentiality<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.rec.ulaval.ca%2Flce%2Fsecurite%2Fconfidentialite.htm&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252367847%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=BeAHrCR9nUGJ2fxRSDRCRg2JX1q6MvSWGyyGn3tOsH4%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252367847%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=VuZqVszOi3ktvRJGXkLAk2FVdYkxxoHgY%2FFRaW2hi3U%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252377844%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0CWXGGTailwE0n%2Bw0KYIc24ounq1ZYyceF6uPgftpJg%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252377844%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0CWXGGTailwE0n%2Bw0KYIc24ounq1ZYyceF6uPgftpJg%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252387836%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=i9adLcJXvEi1VijgcOfBTRjSNLCEOkEVSIgd6boOaZc%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
