HPE6-A84 · Question #18
Refer to the scenario. A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager…
The correct answer is A. An app registration on Azure AD that references the CPPM's FQDN. To use Azure AD as the authentication source in 802.1X services, you need to configure CPPM as a SAML service provider and Azure AD as a SAML identity provider. This allows CPPM to use Azure AD for user authentication and role mapping. To do this, you need to create an app…
Question
Refer to the scenario. A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune). The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10). The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions. You are planning to use Azure AD as the authentication source in 802.1X services. What should you make sure that the customer understands is required?
Options
- AAn app registration on Azure AD that references the CPPM's FQDN
- BWindows 365 subscriptions
- CCPPM's RADIUS certificate was imported as trusted in the Azure AD directory
- DAzure AD Domain Services
How the community answered
(63 responses)- A56% (35)
- B25% (16)
- C5% (3)
- D14% (9)
Explanation
To use Azure AD as the authentication source in 802.1X services, you need to configure CPPM as a SAML service provider and Azure AD as a SAML identity provider. This allows CPPM to use Azure AD for user authentication and role mapping. To do this, you need to create an app registration on Azure AD that references the CPPM's FQDN as the reply URL and the entity ID. You also need to grant the app registration the required permissions to access user information
Topics
Community Discussion
No community discussion yet for this question.