Hybrid Entra ID and on-premises AD deployments

The hybrid Entra ID and on-premises AD deployment model enables secure, flexible authentication and authorization for remote access users, provided the correct policy order and rule configuration are maintained.

In a hybrid deployment, remote access VPN users can authenticate with Microsoft Entra ID (formerly Azure AD). Cisco ISE authorizes the session and Firewall Management Center uses an on-premises Microsoft Active Directory realm for user identity and user-based access control. In this deployment model:

  • Remote access VPN (RA VPN) is configured on Firewall Threat Defense

  • Microsoft Entra ID or Azure is used as the SAML identity provider for VPN authentication

  • Cisco ISE is used for session authorization

  • Cisco ISE authorization policies may include both Microsoft Entra ID/Azure and on-premises AD rules or conditions

  • Firewall Management Center uses the on-premises AD domain as the realm for user identity and user enforcement

Best practice: ISE authorization policy order for hybrid deployments

Beginning with Cisco ISE Release 3.4 Patch 4, when ISE evaluates an Entra ID identity source during authorization, it associates Entra ID attributes with the session. If Firewall Management Center uses an on-premises AD realm, the presence of Entra ID attributes may prevent correct user-to-IP mapping for RA VPN sessions. Identity-based access control rules that depend on user or group identity might not match as expected.

To prevent this issue:

Place ISE authorization rules that use the on-premises AD external identity source before rules that evaluate Entra ID or Azure conditions for the same users. This ensures that the session attributes published to FMC through pxGrid align with the configured on-premises AD realm.

After configuring the authorization policy order, verify that new RA VPN sessions create user mappings in Firewall Management Center and that user-based or group-based access control rules match as expected.

Note

This behavior applies to Cisco ISE Release 3.4 Patch 4 and later. If user mappings stopped appearing after an ISE upgrade, review the ISE authorization policy order as described in this section.