Use ClearPass Azure AD Secure Client / OAuth 2.0 / Graph API with Radius can be solve issue or same also?
-------------------------------------------
Original Message:
Sent: Dec 02, 2025 03:00 PM
From: ahollifield
Subject: Azure AD as ClearPass Authentication Source for TACACS+
No, corporate CA. Internal proper 3 tier offline root PKI. Or a PKIaaS provider.
Original Message:
Sent: 12/2/2025 2:54:00 PM
From: mohamed-nabil
Subject: RE: Azure AD as ClearPass Authentication Source for TACACS+
Certificates signed From Public CA?
Original Message:
Sent: Dec 02, 2025 02:48 PM
From: ahollifield
Subject: Azure AD as ClearPass Authentication Source for TACACS+
You don't. You use SSH keypairs (certificates) or some other user database.
Original Message:
Sent: Dec 02, 2025 02:41 PM
From: mohamed-nabil
Subject: Azure AD as ClearPass Authentication Source for TACACS+
Yes Entra only
Original Message:
Sent: Dec 02, 2025 02:35 PM
From: ahollifield
Subject: Azure AD as ClearPass Authentication Source for TACACS+
What do you mean? What scenario? Is there no on-prem AD sync? This is an Entra only customer?
Original Message:
Sent: Dec 02, 2025 02:31 PM
From: mohamed-nabil
Subject: Azure AD as ClearPass Authentication Source for TACACS+
thanks for your reply
The problem is how to manage switches in that is scenario?
Original Message:
Sent: Dec 02, 2025 07:35 AM
From: ahollifield
Subject: Azure AD as ClearPass Authentication Source for TACACS+
You can't use SAML with TACACS+. TACACS+ is not a browser based application. Entra ID supports SAML natively, there is no need for ClearPass in that flow.
Original Message:
Sent: Dec 02, 2025 02:15 AM
From: mohamed-nabil
Subject: Azure AD as ClearPass Authentication Source for TACACS+
thanks for your reply
What are the requirements for SAML and do I need onboard licenses?
Original Message:
Sent: Dec 01, 2025 03:21 PM
From: mkk
Subject: Azure AD as ClearPass Authentication Source for TACACS+
As far as I know, you cannot use Entra ID as an authentication source for TACACS+. Instead, you can create local user accounts in the ClearPass internal database and use those for TACACS+ authentication.
------------------------------
Marcel Koedijk | MVP Expert 2024 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
Original Message:
Sent: Dec 01, 2025 01:44 PM
From: mohamed-nabil
Subject: Azure AD as ClearPass Authentication Source for TACACS+
what is the requirement from Clearpass & AZURE AD to control managment of Network Devices with TACACS+?
-------------------------------------------