Does NAC have the capability to identify company issued devices by the certificate installed on them and can NAC mesh with Intune?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-16-2016 05:57 PM
We are trying to see what our options or for identifying mobile devices by the certificate installed on them. We would be using Intune to push group policy settings and a cert. Currently the NAC is setup with AD connectivity. Can a rule be built to catch devices with a company issued cert and also would we need to use a particular auth method? Could we use a captive portal or would we need to use 802.1X?
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-16-2016 06:12 PM
You can define rules based on 802.1x method = if EAP-TLS and the certificate is from the right CA then access granted as "company owned device". You can also verify the username (from CN) against LDAP for additional distinguishing...
Regards
Zdeněk Pala
