EAP-TLS is SUPPOSED to only use the certificate for Authentication. You can use Authorization for group lookup.
Hybrid joined devices have their data in Entra ID too. I query Hybrid joined user and device information from Entra ID regularly in my test Lab.
Original Message:
Sent: Jan 08, 2024 11:43 AM
From: wong94886
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
Unfortunately, we have a mixture of AAD joined and hybrid joined machines and that's the reason for 2 Services. It is my understanding that I cannot combine the 2 Services since the Authentication Sources under Authentication has to be empty (see below) or the AAD joined machine authentication will fail.
Original Message:
Sent: Jan 08, 2024 10:26 AM
From: bosborne
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
Are your AD clients Hybrid joined? If so, you should be able to just use Entra ID.
------------------------------
Bruce Osborne ACCP ACMP
Liberty University
The views expressed here are my personal views and not those of my employer
Original Message:
Sent: Jan 07, 2024 09:43 PM
From: wong94886
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
Heman - Thank you for your response. You have definitely provided us with some ideas. Unfortunately, our on-prem AD domain and Entra ID domain are the same. So, what we are considering is doing some sort of prefix or suffix with the hostname to identify the AADJ machine. The question is what condition (Type and Name) in the Service Rule to catch/match the hostname from request. Thanks.
Original Message:
Sent: Jan 05, 2024 05:22 AM
From: Herman Robers
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
What works for me is to catch the computer Authentication for Entra ID/Intune machines with the following service match:

Then the user with a match on your Entra ID domain, which in general is different from your on premise AD domain:

Put these service above your on-premises AD Service. Or match on your on-premise AD user names and let the Entra ID users fall through to services below.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jan 04, 2024 03:33 PM
From: wong94886
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
Thanks for the link. Sorry I did not make myself clear, but I am looking for help around attributes to use in the Service rule to catch the request from AAD joined machine.
Original Message:
Sent: Jan 04, 2024 01:33 PM
From: ahollifield
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
https://www.youtube.com/watch?v=MlcrqTDDufU
Original Message:
Sent: Jan 04, 2024 01:05 PM
From: wong94886
Subject: Creating a Service in ClearPass 6.11 for AADJ machine authentication.
We have a mixture of AAD joined and Hybrid joined machines in our environment. We already have a service created for the hybrid joined machines, but what is the best way to create another service for the AAD joined machines?