Create an Azure AD realm
This task creates a realm (a connection between the Cloud-Delivered Firewall Management Center and a Microsoft Azure AD realm) to enable user and identity control through access control policies.
Note | To perform user and identity control with an Azure AD realm, you need only an access control policy with an associated Azure AD realm. You do not need to create an identity policy. |
Before you begin
Complete all of the following tasks:
-
Configure ISE as discussed in Configure Cisco ISE for Microsoft Azure AD (SAML)Microsoft Azure AD
-
Create an ISE identity source as discussed in ISE/ISE-PIC configuration
-
Get values required for the Azure AD realm as discussed in Get required information For Your Microsoft Azure AD realm.
-
Configure Azure AD as discussed in Configure Microsoft Entra ID for passive authentication
If you enabled Change Management, you must approve all certificates used in this procedure. Open a new ticket or edit an existing one. For more information, see Create change management tickets and .Policies and objects that support change management
Follow these steps to create an Azure AD realm:
Procedure
Step 1 | Click and choose | |||||||||||||||
Step 2 | Click . | |||||||||||||||
Step 3 | To create a new realm, click . | |||||||||||||||
Step 4 | Enter the required information.
| |||||||||||||||
Step 5 | Enter the values you found as discussed in Get required information For Your Microsoft Azure AD realm. | |||||||||||||||
Step 6 | Click Test. | |||||||||||||||
Step 7 | Fix any errors that are displayed in the test. | |||||||||||||||
Step 8 | Click Save. |
What to do next
Create an access control policy and rule as discussed in Creating a basic access control policy.