300-715 · Question #393
A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements: - Users and computers must be authenticated. - User groups must be retr
The correct answer is C. MS-CHAPv2. When authenticating users against Microsoft Active Directory in Cisco ISE, the standard protocol combination is PEAP (Protected EAP) with MS-CHAPv2 as the inner authentication method. MS-CHAPv2 allows ISE to pass credentials to Active Directory for validation and supports retriev
Question
A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements:
- Users and computers must be authenticated.
- User groups must be retrieved during authentication.
Which protocol must be added to the allowed protocols on the policy to authenticate the users?
Options
- AEAP-TLS
- BEAP-GTC
- CMS-CHAPv2
- DLEAP
How the community answered
(26 responses)- A4% (1)
- B4% (1)
- C92% (24)
Explanation
When authenticating users against Microsoft Active Directory in Cisco ISE, the standard protocol combination is PEAP (Protected EAP) with MS-CHAPv2 as the inner authentication method. MS-CHAPv2 allows ISE to pass credentials to Active Directory for validation and supports retrieval of user group membership - satisfying both requirements. EAP-TLS (A) uses certificate-based authentication, not AD username/password credentials. EAP-GTC (B) is typically used with RSA SecurID or OTP tokens, not AD. LEAP (D) is a deprecated Cisco-proprietary protocol. MS-CHAPv2 must be enabled in the allowed protocols list under the ISE policy set so that PEAP/MS-CHAPv2 negotiations can succeed against AD.
Topics
Community Discussion
No community discussion yet for this question.