300-715 · Question #356
Using the SAML protocol, an administrator must configure the Cisco ISE Sponsor portal to authenticate users with an external Microsoft Active Directory Federation Services server. The configurations…
The correct answer is B. Configure an identity source sequence in the Sponsor portal E. Add SAML identity provider groups in Sponsor Group Members. To complete SAML integration for the Cisco ISE Sponsor portal with an ADFS server, an identity source sequence must be configured in the portal, and SAML identity provider groups must be added to Sponsor Group Members.
Question
Using the SAML protocol, an administrator must configure the Cisco ISE Sponsor portal to authenticate users with an external Microsoft Active Directory Federation Services server. The configurations were performed:
- created a new SAML identity provider profile in Cisco ISE
- exported the service provider information
- configured all the required Active Directory Federation Services
configurations
- imported the Active Directory Federation Services metadata
- configured groups in the new SAML identity provider profile
- added attributes to the new SAML identity provider profile
- configured Advanced Settings in the new SAML identity provider
profile Which two actors must be taken to complete the configuration? (Choose two.)
Options
- AConfigure the Sponsor portal HTTPS port for Active Directory Federation Services integration
- BConfigure an identity source sequence in the Sponsor portal
- CAllow Kerberos single sign-on on the Sponsor portal
- DCustomize the Sponsor portal pages for integration with Active Directory Federation Services
- EAdd SAML identity provider groups in Sponsor Group Members
How the community answered
(50 responses)- A4% (2)
- B74% (37)
- C6% (3)
- D16% (8)
Why each option
To complete SAML integration for the Cisco ISE Sponsor portal with an ADFS server, an identity source sequence must be configured in the portal, and SAML identity provider groups must be added to Sponsor Group Members.
The HTTPS port for the Sponsor portal is a network configuration detail and is not a direct step in configuring the SAML authentication flow with ADFS.
Configuring an identity source sequence in the Sponsor portal is crucial to define the order of identity sources, including the new SAML IdP profile, used for user authentication. This ensures the Sponsor portal directs authentication requests to ADFS as intended.
Kerberos single sign-on is a separate authentication mechanism and is not directly relevant to configuring SAML authentication with ADFS for the Sponsor portal.
Customizing Sponsor portal pages is typically for branding or user experience improvements and is not a mandatory technical step for enabling SAML authentication with ADFS.
Adding SAML identity provider groups to Sponsor Group Members allows Cisco ISE to map groups asserted by ADFS via SAML to specific Sponsor portal access rights or roles. This step is necessary to authorize authenticated users based on their SAML group memberships to use the portal.
Concept tested: Cisco ISE Sponsor Portal SAML Integration with ADFS
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_30_admin_guide/b_ise_30_admin_guide_chapter_01001.html#concept_75D7EAE37138407384A2209355609B17
Topics
Community Discussion
No community discussion yet for this question.