Security

 View Only
Expand all | Collapse all

Is ClearPass Guest Sponsor lookup possible with Microsoft Entra Domain Services (AD DS) as LDAP directory?

This thread has been viewed 20 times
  • 1.  Is ClearPass Guest Sponsor lookup possible with Microsoft Entra Domain Services (AD DS) as LDAP directory?

    Posted Jul 29, 2025 08:53 AM

    Hi

    I have a few customers with ClearPass Guest sponsor lookup configured and the on-prem AD is the LDAP source for the sponsor search.

    Now the customers are planning to decommission the on-prem Active Directory, and thus the sponsor lookup will stop working as Entra ID isn't an LDAP directory. Is it possible to tell the customer to configure Microsoft Entra Domain Services (AD DS) and utilize this service as the LDAP directory for the sponsor lookup?

    Have anyone tried it and are there any caveats?



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------


  • 2.  RE: Is ClearPass Guest Sponsor lookup possible with Microsoft Entra Domain Services (AD DS) as LDAP directory?

    Posted Jul 30, 2025 10:53 AM

    Hi,

    We are doing this using SSO. It is much better and works fine! The user types in the URL and gets an Azure authentication window. He authenticates and then is directed to Guest page.

    You have to create an Enterprise Application in Azure and use SAML.

    Application type: Non-Gallery Application
    Mode: SAML based Sign on

    In the CP Login service you map the logged in user to a role and then  in ClearPass Guest you need to create an Operator Translation Rule for that role.

    Best Regards

    Istvan

    -------------------------------------------



  • 3.  RE: Is ClearPass Guest Sponsor lookup possible with Microsoft Entra Domain Services (AD DS) as LDAP directory?

    Posted Jul 31, 2025 02:32 AM

    Hi @Istvan Hegedus

    I'm not sure if we are talking about the same thing here. I'm taking about the search function you can enable on a guest self registration page where the guest can start type the name of the person in the company they are visiting and the form will search for matches in the LDAP directory.

    I think you refer to the sponsor login for approval.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: Is ClearPass Guest Sponsor lookup possible with Microsoft Entra Domain Services (AD DS) as LDAP directory?

    Posted Aug 01, 2025 03:25 AM

    Hi,

    Yes that is totally different. Sorry.

    Br

    Istvan

    -------------------------------------------