>While the MX supports AnyConnect, it does not support RADIUS Challenge. This prompts the user for the type of 2FA authentication they want, a Push, Text or Call.
I don't know the answer - but interesting question.
Personally, I don't see much use for this feature anymore. Everyone is changing over to SAML based authentication (instead of RADIUS). Once you do that, AnyConnect uses a web page for authentication, and your SAML provider can display, ask or challenge in any way that it wants.
I did a Google and found several hits for "ISE" and "SAML", so it may be that ISE supports it. Personally, I've done most of my SAML implementations using either Cisco DUO or Azure AD.
If you use Cisco Duo and have the "Beyond" plan you can also do a posture assessment at the same time.
And because SAML is SSO, once you authenticate using AnyConnect in this way, you are also automatically authenticated to every SAML app you use (Office 365, Salesforce, etc) so the user doesn't have to sign in again.
So maybe the question might not be when Cisco Meraki is adding support for a method that is dying out - but when you are modernizing your authentication method to what everyone is using .... 🙂