In this short video, ISE TME Hosuk Won shows you how to quickly configure single sign on administrator access to ISE using Azure AD in ISE 3.1. For more information on ISE, be sure to check out the online community at http://cs.co/ise-community.
Video Notes and FAQ:
If you get 400 error upon clicking Admin SSO from the ISE login page after the configuration: This is a known issue. To work around the issue create a dummy SAML Identity source on ISE and map it to the admin access. Save it, then change it back to the correct SAML identity source.
If certain pages under SAML identity source on ISE doesn’t save after clicking on save or Submit, refresh the browser window and retry the operation again
If using Chrome browser, SAML-Tracer extension can be very useful in validating if Azure AD is sending proper group claims
Even after validating the proper group claim is being sent, you still cannot login with SSO user to the admin console, try with an incognito or private browser window
For distributed deployment, make sure to add every PSN persona entry for the reply URL based on both the host names and IP addresses under Azure AD enterprise application SingleSign-On SAML configuration