Isn’t SAML entirely a web-based thing?  Sure, you can tie it into the actual 
website URL of your ASA, but what about logging in directly from the AnyConnect 
client itself?  This is not referenced in any documents I’ve seen so far.  Is 
this possible?

website login for AnyConnect would be unfriendly to many users who are already 
hostile to having to use VPN in the first place.



My research on the topic is that many people are going to ISE 3.0 and using PAP 
to go to Azure AD for RA AnyConnect.  Additionally Azure AD doesn’t seem to 
support PEAP-MSCHAPv2 right now, which does directly concern wireless.  (and 
yes I know EAP-TLS is the the way that it “should” be done, but the “should" 
doesn’t materialize into reality for many people.  Many simply are not in a 
position to roll out EAP-TLS)

Azure AD seems to be designed with Cloud web-apps in mind only, and this 
apparently is creating alot of gaps on the Networking end, and Microsoft is not 
in the Networking business to care.


Please correct me on any point, I do have alot of knowledge gaps on this 
subject.


-
Matt







On Aug 26, 2021, at 9:14 AM, Jeffrey D. Sessler 
<[email protected]<mailto:[email protected]>> wrote:

WARNING: This email originated external to the NMSU email system. Do not click 
on links or open attachments unless you are sure the content is safe.
I 2nd Tim’s suggestion.  If the VPN is Cisco-based, they support using SAML 
against AzureAD including MFA.

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215935-configure-asa-anyconnect-vpn-with-micros.html

Jeff

From: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]<mailto:[email protected]>> 
on behalf of Manon Lessard 
<[email protected]<mailto:[email protected]>>
Date: Thursday, August 26, 2021 at 7:54 AM
To: 
[email protected]<mailto:[email protected]> 
<[email protected]<mailto:[email protected]>>
Subject: Re: [WIRELESS-LAN] ISE-NPS-Azure MFA
We are talking VPN here and for the entire campus…

Manon Lessard
Chargée de programmation et d’analyse
CCNP, CWNE #275, AWA 10, ESCE Design
Direction des technologies de l'information
Pavillon Louis-Jacques-Casault
1055, avenue du Séminaire
Bureau 0403
Université Laval, Québec (Québec)
G1V 0A6, Canada
418 656-2131, poste 412853
Télécopieur : 418 656-7305
[email protected]<mailto:[email protected]>
www.dti.ulaval.ca<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.dti.ulaval.ca%2F&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252337862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=%2FfwassNcb%2F%2BSGKqQ82Se5KxpAUoBFPbPtZDbU7Uylm4%3D&reserved=0>
Avis relatif à la confidentialité | Notice of 
Confidentiality<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.rec.ulaval.ca%2Flce%2Fsecurite%2Fconfidentialite.htm&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252347857%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=yi11CEEfHsdZlahlQGe89SW7lkOpikhLlSbTGS7%2BZQg%3D&reserved=0>


From: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]<mailto:[email protected]>> 
on behalf of James Andrewartha 
<[email protected]<mailto:[email protected]>>
Reply-To: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]<mailto:[email protected]>>
Date: Thursday, August 26, 2021 at 10:50 AM
To: 
"[email protected]<mailto:[email protected]>" 
<[email protected]<mailto:[email protected]>>
Subject: Re: [WIRELESS-LAN] ISE-NPS-Azure MFA

Microsoft note this behaviour and have some sort of workaround in their NPS MFA 
extension: 
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension#radius-protocol-behavior-and-the-nps-extension<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-mfa-nps-extension%23radius-protocol-behavior-and-the-nps-extension&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252347857%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=ftbr5gySi10k6XMgZeL%2B48rmHs4dWCx4LAiv%2Bw%2BByUw%3D&reserved=0>

Really though, doing MFA for RADIUS is a square peg in a round hole, use MFA to 
provision a client cert and do EAP-TLS instead.

From: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]<mailto:[email protected]>> 
on behalf of Manon Lessard 
<[email protected]<mailto:[email protected]>>
Reply to: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]<mailto:[email protected]>>
Date: Thursday, 26 August 2021 at 10:20 pm
To: 
"[email protected]<mailto:[email protected]>" 
<[email protected]<mailto:[email protected]>>
Subject: [WIRELESS-LAN] ISE-NPS-Azure MFA

A question not directly related to Wi-Fi, but related to ISE which seems to be 
something some of you use.

We are currently authenticating a VPN test group via ISE through NPS servers 
(defined as a token server).
The goal is to do MFA with Azure through the Authenticator app on people’s 
phones.
Everything works, but Authenticator pops up for confirmation, sometimes 2 to 3 
times, even if one has accepted the first confirmation…

I would like to have feedback from people who used something like that and have 
solved the multiple Authenticator prompts.

Thank you

Manon Lessard
Chargée de programmation et d’analyse
CCNP, CWNE #275, AWA 10, ESCE Design
Direction des technologies de l'information
Pavillon Louis-Jacques-Casault
1055, avenue du Séminaire
Bureau 0403
Université Laval, Québec (Québec)
G1V 0A6, Canada
418 656-2131, poste 412853
Télécopieur : 418 656-7305
[email protected]<mailto:[email protected]>
www.dti.ulaval.ca<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.dti.ulaval.ca%2F&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252357849%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0VUJKjfPG2MwvHpbdjDbPOwYYly0PcbeI8AJm%2BKVmRs%3D&reserved=0>
Avis relatif à la confidentialité | Notice of 
Confidentiality<https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.rec.ulaval.ca%2Flce%2Fsecurite%2Fconfidentialite.htm&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252367847%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=BeAHrCR9nUGJ2fxRSDRCRg2JX1q6MvSWGyyGn3tOsH4%3D&reserved=0>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252367847%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=VuZqVszOi3ktvRJGXkLAk2FVdYkxxoHgY%2FFRaW2hi3U%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252377844%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0CWXGGTailwE0n%2Bw0KYIc24ounq1ZYyceF6uPgftpJg%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252377844%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=0CWXGGTailwE0n%2Bw0KYIc24ounq1ZYyceF6uPgftpJg%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cmatcraig%40nmsu.edu%7Cbc3bcb57a0ee44d7f87208d968a45373%7Ca3ec87a89fb84158ba8ff11bace1ebaa%7C1%7C0%7C637655877252387836%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=i9adLcJXvEi1VijgcOfBTRjSNLCEOkEVSIgd6boOaZc%3D&reserved=0>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Reply via email to