nerdexam
Cisco

300-740 · Question #30

Refer to the exhibit. An engineer must configure SAML SSO in Cisco ISE to use Microsoft Azure AD as an identity provider. These configurations were performed: - Configure a SAML IdP in ISE…

The correct answer is B. Upload metadata from Azure AD to ISE. E. Configure the Internal Identity Source Sequence setting. Uploading Azure AD metadata to ISE (B) completes the SAML trust relationship - ISE needs Azure AD's federation metadata (endpoints, signing certificates, entity ID) to validate assertions coming from the IdP. Configuring the Identity Source Sequence (E) is required so ISE knows…

User and Device Security

Question

Refer to the exhibit. An engineer must configure SAML SSO in Cisco ISE to use Microsoft Azure AD as an identity provider. These configurations were performed:

  • Configure a SAML IdP in ISE.
  • Configure the Azure AD IdP settings.

Which two actions must the engineer take in Cisco ISE? (Choose two.)

Exhibit

300-740 question #30 exhibit

Options

  • AAdd a SAML IdP.
  • BUpload metadata from Azure AD to ISE.
  • CConfigure SAML groups in ISE.
  • DConfigure the External Identity Sources settings.
  • EConfigure the Internal Identity Source Sequence setting.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    77% (27)
  • C
    9% (3)
  • D
    11% (4)

Explanation

Uploading Azure AD metadata to ISE (B) completes the SAML trust relationship - ISE needs Azure AD's federation metadata (endpoints, signing certificates, entity ID) to validate assertions coming from the IdP. Configuring the Identity Source Sequence (E) is required so ISE knows to use the SAML IdP when processing authentication requests through its policy engine; without this step, SAML is configured but never invoked.

Why the distractors are wrong:

  • A is already done - "Configure a SAML IdP in ISE" from the exhibit covers adding the IdP entry.
  • C (SAML groups) may be needed for role mapping in some deployments, but it is not a mandatory step to establish the basic SAML SSO flow described here.
  • D (External Identity Sources settings) is implicitly handled when the SAML IdP is added - there is no separate "External Identity Sources" configuration step required after the IdP is already defined.

Memory tip: Think of SAML setup as a two-way handshake - ISE gives its SP metadata to Azure AD, and Azure AD gives its IdP metadata back to ISE (option B). Then you must "wire it in" to ISE's policy engine via the Identity Source Sequence (option E), or the IdP just sits there unused.

Topics

#SAML SSO#ISE Configuration#Azure AD Integration#Identity Management

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice