Cloud Managed Networks

 View Only
Expand all | Collapse all

Cloud auth - onboarding cert works on another machine

This thread has been viewed 15 times
  • 1.  Cloud auth - onboarding cert works on another machine

    Posted Oct 19, 2023 11:03 AM

    Hello 

    We have  Aruba central setup using cloud auth, everything works fine however it appears if I copy the passpoint download from an onboarded laptop to a freshly imaged laptop I can join the wireless network without even authenticating, 

    Now I understand to get the passpoint download i would need to download the app, authenticate if its a non domain laptop but being able to connect to the wifi by copying the file is a big concern has anyone else seen this ?

    is it normal for the onboarding app not to ask to authenticate on a domain joined machine ?



  • 2.  RE: Cloud auth - onboarding cert works on another machine

    Posted Oct 20, 2023 11:14 AM

    If you are authenticated to Azure/Office 365 in the same browser where you trigger the onboarding, it's expected that you don't need to authenticate again as the Office 365 authentication is used. That should not be related to if the computer is domain joined or not, but if the computer is Entra ID joined (formerly known as Azure AD) it may be that some browsers will auto-sign in to Office 365/Microsoft account.

    I have not tested that myself, but I think with a Conditional Access policy in Entra ID, you could prevent that automatic sign in and enforce a multi-factor or re-login.

    Note that Cloud Authentication and policy is designed for BYOD devices, if you have domain/Entra ID joined computers you probably would automate the onboarding process with group policies/Intune and use ClearPass or similar.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------