<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AzureAd and dot1X in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95239#M9797</link>
    <description>&lt;P&gt;There are many flavors of 802.1X.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EAP-TLS can still be used with Azure, certificates are independent of Azure.&lt;/LI&gt;&lt;LI&gt;The PEAP with MsChapv2 can not be used with Azure cloud as NTLM is not supported there and NTLM can not be translated to SAML/API calls.&lt;/LI&gt;&lt;LI&gt;If customers want to use PEAP, they deploy local AD with Azure connector to synchronize. Local AD can be used for NTLM or NPS.&lt;/LI&gt;&lt;LI&gt;We are investigating EAP-TTLS with PAP option as it can be used with Azure cloud as the password can be translated to SAML/API calls to Azure. This is not available with the current version of ExtremeControl.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2023 13:44:30 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2023-03-20T13:44:30Z</dc:date>
    <item>
      <title>AzureAd and dot1X</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95236#M9795</link>
      <description>&lt;P&gt;About to start looking for other solutions now.&lt;/P&gt;&lt;P&gt;We have been using ExtremeControl for some years for .1x logon with both wireless and wired network.&lt;/P&gt;&lt;P&gt;But now we are moving towards AzureAD&amp;nbsp; (currently hybrid). So for now we see a lot of problems with&lt;/P&gt;&lt;P&gt;logins.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1: AzureAD joined PC's are not visible to the NAC.&lt;/P&gt;&lt;P&gt;2: UserAuth works, but it is far from flawless. (had to install NPS proxy because of UPN)&lt;/P&gt;&lt;P&gt;3: Intune plugin is useless because it only does mac-auth based on the wifi mac address on the device. so there will be no workable wired auth. (apart from userAuth).&lt;/P&gt;&lt;P&gt;This has been a problem now since 2019. What are ExtremeNetworks going to do with this ?&lt;/P&gt;&lt;P&gt;Has anybody found a good soloution on this problem ? (I see that sombody asked question as early as 2018)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 11:33:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95236#M9795</guid>
      <dc:creator>faste</dc:creator>
      <dc:date>2023-03-20T11:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: AzureAd and dot1X</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95239#M9797</link>
      <description>&lt;P&gt;There are many flavors of 802.1X.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EAP-TLS can still be used with Azure, certificates are independent of Azure.&lt;/LI&gt;&lt;LI&gt;The PEAP with MsChapv2 can not be used with Azure cloud as NTLM is not supported there and NTLM can not be translated to SAML/API calls.&lt;/LI&gt;&lt;LI&gt;If customers want to use PEAP, they deploy local AD with Azure connector to synchronize. Local AD can be used for NTLM or NPS.&lt;/LI&gt;&lt;LI&gt;We are investigating EAP-TTLS with PAP option as it can be used with Azure cloud as the password can be translated to SAML/API calls to Azure. This is not available with the current version of ExtremeControl.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 13:44:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95239#M9797</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2023-03-20T13:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: AzureAd and dot1X</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95248#M9799</link>
      <description>&lt;P&gt;Problem with PEAP /Local AD is that upn is not supported and i've also seen other users having problem with authentication. And as you said. NPS Might be a solution. But in my experience the devices tend to try to authenticate with host/xxx instead of user/xxx and then the user does not get access.&lt;/P&gt;&lt;P&gt;EAP-TLS might be a solution, but then that will only give us the host-id (And it will require a step in installing dev-certs to azure ad joined devices before they are present on network ) .&lt;/P&gt;&lt;P&gt;When will the EAP TTLS/PAP solution be ready, and what will it require of the azure account ? E3/E5 ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 08:31:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/azuread-and-dot1x/m-p/95248#M9799</guid>
      <dc:creator>faste</dc:creator>
      <dc:date>2023-03-21T08:31:51Z</dc:date>
    </item>
  </channel>
</rss>

