nerdexam
Cisco

300-715 · Question #356

Using the SAML protocol, an administrator must configure the Cisco ISE Sponsor portal to authenticate users with an external Microsoft Active Directory Federation Services server. The configurations…

The correct answer is B. Configure an identity source sequence in the Sponsor portal E. Add SAML identity provider groups in Sponsor Group Members. To complete SAML integration for the Cisco ISE Sponsor portal with an ADFS server, an identity source sequence must be configured in the portal, and SAML identity provider groups must be added to Sponsor Group Members.

Web Auth and Guest Services

Question

Using the SAML protocol, an administrator must configure the Cisco ISE Sponsor portal to authenticate users with an external Microsoft Active Directory Federation Services server. The configurations were performed:

  • created a new SAML identity provider profile in Cisco ISE
  • exported the service provider information
  • configured all the required Active Directory Federation Services

configurations

  • imported the Active Directory Federation Services metadata
  • configured groups in the new SAML identity provider profile
  • added attributes to the new SAML identity provider profile
  • configured Advanced Settings in the new SAML identity provider

profile Which two actors must be taken to complete the configuration? (Choose two.)

Options

  • AConfigure the Sponsor portal HTTPS port for Active Directory Federation Services integration
  • BConfigure an identity source sequence in the Sponsor portal
  • CAllow Kerberos single sign-on on the Sponsor portal
  • DCustomize the Sponsor portal pages for integration with Active Directory Federation Services
  • EAdd SAML identity provider groups in Sponsor Group Members

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    74% (37)
  • C
    6% (3)
  • D
    16% (8)

Why each option

To complete SAML integration for the Cisco ISE Sponsor portal with an ADFS server, an identity source sequence must be configured in the portal, and SAML identity provider groups must be added to Sponsor Group Members.

AConfigure the Sponsor portal HTTPS port for Active Directory Federation Services integration

The HTTPS port for the Sponsor portal is a network configuration detail and is not a direct step in configuring the SAML authentication flow with ADFS.

BConfigure an identity source sequence in the Sponsor portalCorrect

Configuring an identity source sequence in the Sponsor portal is crucial to define the order of identity sources, including the new SAML IdP profile, used for user authentication. This ensures the Sponsor portal directs authentication requests to ADFS as intended.

CAllow Kerberos single sign-on on the Sponsor portal

Kerberos single sign-on is a separate authentication mechanism and is not directly relevant to configuring SAML authentication with ADFS for the Sponsor portal.

DCustomize the Sponsor portal pages for integration with Active Directory Federation Services

Customizing Sponsor portal pages is typically for branding or user experience improvements and is not a mandatory technical step for enabling SAML authentication with ADFS.

EAdd SAML identity provider groups in Sponsor Group MembersCorrect

Adding SAML identity provider groups to Sponsor Group Members allows Cisco ISE to map groups asserted by ADFS via SAML to specific Sponsor portal access rights or roles. This step is necessary to authorize authenticated users based on their SAML group memberships to use the portal.

Concept tested: Cisco ISE Sponsor Portal SAML Integration with ADFS

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_30_admin_guide/b_ise_30_admin_guide_chapter_01001.html#concept_75D7EAE37138407384A2209355609B17

Topics

#SAML Integration#ISE Sponsor Portal#Identity Source Configuration#Sponsor Group Authorization

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice