Security

 View Only
  • 1.  Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 04, 2024 01:05 PM

    We have a mixture of AAD joined and Hybrid joined machines in our environment.  We already have a service created for the hybrid joined machines, but what is the best way to create another service for the AAD joined machines?



  • 2.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 04, 2024 01:34 PM

    https://www.youtube.com/watch?v=MlcrqTDDufU




  • 3.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 04, 2024 03:34 PM

    Thanks for the link.  Sorry I did not make myself clear, but I am looking for help around attributes to use in the Service rule to catch the request from AAD joined machine.




  • 4.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 05, 2024 05:22 AM

    What works for me is to catch the computer Authentication for Entra ID/Intune machines with the following service match:

    Then the user with a match on your Entra ID domain, which in general is different from your on premise AD domain:

    Put these service above your on-premises AD Service. Or match on your on-premise AD user names and let the Entra ID users fall through to services below.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 07, 2024 09:43 PM

    Heman - Thank you for your response.  You have definitely provided us with some ideas.  Unfortunately, our on-prem AD domain and Entra ID domain are the same.  So, what we are considering is doing some sort of prefix or suffix with the hostname to identify the AADJ machine.  The question is what condition (Type and Name) in the Service Rule to catch/match the hostname from request.  Thanks.




  • 6.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 08, 2024 10:26 AM

    Are your AD clients Hybrid joined? If so, you should be able to just use Entra ID.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 7.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 08, 2024 11:43 AM

    Unfortunately, we have a mixture of AAD joined and hybrid joined machines and that's the reason for 2 Services.  It is my understanding that I cannot combine the 2 Services since the Authentication Sources under Authentication has to be empty (see below) or the AAD joined machine authentication will fail. 




  • 8.  RE: Creating a Service in ClearPass 6.11 for AADJ machine authentication.

    Posted Jan 08, 2024 12:07 PM

    EAP-TLS is SUPPOSED to only use the certificate for Authentication. You can use Authorization for group lookup.

    Hybrid joined devices have their data in Entra ID too. I query Hybrid joined user and device information from Entra ID regularly in my test Lab.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------