<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Implement Microsoft Entra ID Registration with OpenID in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112517#M851</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Are you allowing client traffic out to Microsoft through the walled garden on the policy on the controller or switch?&lt;BR /&gt;&lt;BR /&gt;The button should redirect the client out to login.microsoftonline.com, if the client has access to this resource blocked.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 12:52:21 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2024-09-06T12:52:21Z</dc:date>
    <item>
      <title>How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112491#M850</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've updated my XIQ-SE + ExtremeControl to latest version&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="xiq-se_version.PNG" style="width: 323px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8134iD73B367973247A1F/image-size/large?v=v2&amp;amp;px=999" role="button" title="xiq-se_version.PNG" alt="xiq-se_version.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and I'm trying&amp;nbsp;&lt;A title="How to Implement Microsoft Entra ID Registration with OpenID" href="http://How to Implement Microsoft Entra ID Registration with OpenID" target="_blank" rel="noopener"&gt;How to Implement Microsoft Entra ID Registration with OpenID&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured Captive Portal for Entra ID registration and the test is successful&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="caprive portal conf for web user entra id.PNG" style="width: 929px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8135iB15167671E6BB3C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="caprive portal conf for web user entra id.PNG" alt="caprive portal conf for web user entra id.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've added the nac rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nac rule.PNG" style="width: 468px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8136i088E292B57126B2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="nac rule.PNG" alt="nac rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But on the client, when press the Button "Sign in with Microsoft" nothing happen (network login and Register as Guest works instead).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="captive portal.PNG" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8137i3D13AE3BA00B6703/image-size/large?v=v2&amp;amp;px=999" role="button" title="captive portal.PNG" alt="captive portal.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I debug what's the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 09:26:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112491#M850</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2024-09-06T09:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112517#M851</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Are you allowing client traffic out to Microsoft through the walled garden on the policy on the controller or switch?&lt;BR /&gt;&lt;BR /&gt;The button should redirect the client out to login.microsoftonline.com, if the client has access to this resource blocked.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:52:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112517#M851</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2024-09-06T12:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112547#M852</link>
      <description>&lt;P&gt;both the Access Control Engine and the client must have access to the Microsoft&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 17:19:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112547#M852</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-09-06T17:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112576#M853</link>
      <description>&lt;P&gt;Hi Ryan and Zdenek,&lt;/P&gt;&lt;P&gt;I've added login.microsftonline.com to the allowed URL and domain in the network settings and allowed web of the captive portal&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="allowed_domains.PNG" style="width: 484px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8152iDF2A592165584A9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="allowed_domains.PNG" alt="allowed_domains.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="allowed_web_sites.PNG" style="width: 656px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8153iDEF25CEC95628588/image-size/large?v=v2&amp;amp;px=999" role="button" title="allowed_web_sites.PNG" alt="allowed_web_sites.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but when I click on the Microsoft login button the redirection to microsoft site doesn't happen.&lt;/P&gt;&lt;P&gt;If in the web client browser I try to go to &lt;A href="https://login.microsoftonline.com" target="_blank"&gt;https://login.microsoftonline.com&lt;/A&gt;&amp;nbsp;I've a redirect page but empty:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="loginmicrosofonlien_page.PNG" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8154i52CDE2EE8C8835E6/image-size/large?v=v2&amp;amp;px=999" role="button" title="loginmicrosofonlien_page.PNG" alt="loginmicrosofonlien_page.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Probally I don't put the Allowed web site in the correct format ....How debug more deep the problem?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 08:18:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112576#M853</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2024-09-07T08:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112671#M859</link>
      <description>&lt;P&gt;I want to add the result of a new test I've made: I've added in the allowed website the following domains: msauth.net and office.com and now If in the browser of the unauthenticated client type: &lt;A href="https://login.microsoftonline.com" target="_blank"&gt;https://login.microsoftonline.com&lt;/A&gt;&amp;nbsp;I'm redirected to the login page of Office 365 and after the username and password I'm lgged in to office 365.&lt;/P&gt;&lt;P&gt;Instead if I press the button for Window auth on the NAC authentication page of the Captive Web Portal , nothing happens...&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 13:20:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112671#M859</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2024-09-07T13:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112728#M861</link>
      <description>&lt;P&gt;can you elaborate more on "&lt;SPAN&gt;nothing happens&lt;/SPAN&gt;"? The button should open Microsoft web. are you waiting long enough to see 404 page? in case your policy is blocking the traffic? When you do a packet capture on the client what is happening? do you see attempt of the connection from the web browser?&lt;/P&gt;&lt;P&gt;As a troubleshooting step, you can permit all HTTPs traffic (HTTP will be redirected to the captive portal, but HTTPs will not be blocked). You can eliminate the problem with policy definition.&lt;/P&gt;&lt;P&gt;Can you also check you can reach the Microsoft pages from the access control engine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2024 19:11:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112728#M861</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-09-08T19:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112729#M862</link>
      <description>&lt;P&gt;The communication is between the web browser on the client and Microsoft.&amp;nbsp; Setting "Allowed Sites" in the ExtremeControl is used when the traffic is proxied through the Access Control Engine. I do not expect any behavior change if you change the "Allowed Sites" list.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2024 19:16:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112729#M862</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-09-08T19:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112879#M869</link>
      <description>&lt;P&gt;Hi Zdenek,&lt;/P&gt;&lt;P&gt;when I press the "SIgn in with Microsoft" button, in my wireshark session on the client, I don't see DNS request for any microsoft websites, seems that there is no redirection to the login page of microsoft and I don't see client connections to microsoft website at all.&lt;/P&gt;&lt;P&gt;In my configuration for the redirection I use the "Proxy DNS" method because my lab router (pfsense) seems not works with PBR.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 15:03:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112879#M869</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2024-09-09T15:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112951#M871</link>
      <description>&lt;P&gt;Hi Zdenek,&lt;/P&gt;&lt;P&gt;I've modified the configuration in my lab in manner that now I redirect to ExtremeControl Captive portal with PBR, but the behavior is still the same. In the wireshark on the client when I click on the Log in with Microsoft button nothing happens (seems there is no code binded to the button but sure is problem in mi case because in your works).&lt;/P&gt;&lt;P&gt;I can debug the code\script that is under this button on the portal page?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 08:53:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112951#M871</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2024-09-10T08:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to Implement Microsoft Entra ID Registration with OpenID</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112965#M873</link>
      <description>&lt;P&gt;Hi Antonio.&lt;/P&gt;&lt;P&gt;I did not test the Entra ID with PBR.&lt;/P&gt;&lt;P&gt;Regarding troubleshooting/debugging, I suggest opening a GTAC ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 19:17:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/how-to-implement-microsoft-entra-id-registration-with-openid/m-p/112965#M873</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-09-10T19:17:42Z</dc:date>
    </item>
  </channel>
</rss>

