Security

 View Only
  • 1.  Guest authentication with Entra ID

    Posted Jan 23, 2025 04:44 AM

    Hi

    A customer has requested an option for the employees to connect the personal devices to the guest network and instead of register a guest account perform Entra ID based authentication.

    I have created a separate login page in ClearPass Guest and added the Social login configuration as shown below:

    When the login page is accessed the button for Entra ID authentication is displayed, but still with the name Azure AD. I will remove the Username and Password boxes.

    After pressing the Microsoft Azure AD button the following error message is displayed:

    I can't see what field I need to add. I have also prepared a service for Social login in Policy Manager.

    According to a blog post found on the Internet I have completed the needed steps:
    https://whyfiplusplus.wordpress.com/2020/11/10/clearpass-tiny-bite-8-clearpass-guest-social-login-with-azure-ad-part-2/

    I suppose I have missed some steps, but can't find any documentation. What do I need to do more to complete the process for Guest authentication with Entra ID?



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------


  • 2.  RE: Guest authentication with Entra ID

    Posted Jan 23, 2025 10:01 AM

    The error is showing when you click on the Azure AD button?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Guest authentication with Entra ID

    Posted Jan 23, 2025 12:51 PM

    Yes, that's correct. The error message appears when the Microsoft Azure AD button is clicked.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: Guest authentication with Entra ID

    Posted Jan 23, 2025 05:23 PM

    Unless someone else can pipe up with an answer, I'd recommend a case with TAC.   Been many years since the last time I had to configure social login.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Guest authentication with Entra ID

    Posted Jan 29, 2025 07:02 AM

    Required field unavailable may be the client MAC address. If you are testing this, but without the actual redirect, there is no MAC address known. You can try to add ?mac=00:00:00:00:00:00 to the URL, if there are no attributes yet or if there is already a ?something, add &mac=00:00:00:00:00:00 at the end.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: Guest authentication with Entra ID

    Posted Jan 29, 2025 07:47 AM

    Thank you, I will try this



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------