Entra ID Native Integration with Meraki – Clarification Needed

MauroF
Building a reputation

Entra ID Native Integration with Meraki – Clarification Needed

Hi all,

I saw that there is finally native support for Entra ID authentication over Wi-Fi ,great news!

However, I’m still not sure how to actually link Meraki with Entra ID.

I found some documentation on how to configure the SSID, but I couldn't find where the Entra ID connection to Meraki is set up.
Did I miss something?

Thanks,
Greg

10 Replies 10
RWelch
Kind of a big deal
Kind of a big deal

How to Authenticate onto Meraki WiFi with Microsoft Entra ID (Native) 
Perhaps this will help?

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
MauroF
Building a reputation

HI there,

what you sent me is a integration with System Manager which has a different procedure. Thanks anyway.

Mloraditch
Kind of a big deal
Kind of a big deal

If you are talking about Splash Pages that's here: https://documentation.meraki.com/MR/Encryption_and_Authentication/Microsoft_Entra_ID_Integration_wit...

If you are talking about non splash that is part of Access Manager: https://documentation.meraki.com/Access_Manager

 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
MauroF
Building a reputation

The first link is the one i found on internet and its recently new. What i dont understand is, in that in the documenti dont understsand the association between my Meraki and Entra-ID.. I mean where i say to my meraki to go to my entra-id or from my entra-id to get info from my meraki? This is the question.

PhilipDAth
Kind of a big deal
Kind of a big deal

The first thing to note is that you need an "MR Advanced" licence.

 

When you attach to WiFi a web browser will pop up and redirected to the Entra ID login page.  Entra ID will ask you to authenticate.  It will then tell Meraki you are allowed access.

terhan
Conversationalist

The documentation states that its doable with a MR Enterprise licence...
 Microsoft Entra ID Integration with Splash Page - Cisco Meraki Documentation

Brash
Kind of a big deal
Kind of a big deal

The 'association' is via Enterprise Application.

 

Meraki have created a template enterprise application called "Cisco Meraki Network Access"

Deploying this into your tenant and giving admin consent means that when a user connects to your WiFi with the appropriate SSID configuration, an Entra login screen is shown. The user puts in their email - which will identify the corresponding MS domain/tenant for Meraki backend to connect to and send the auth information through to complete the auth process.

MauroF
Building a reputation

".. when a user connects to your WiFi with the appropriate SSID configuration"  but there is no sign of the SSID configuration i should match on Entra-Id. Are your sure about that? if yes ,where should i insert that detail? i doubt its that detail thou.

Mloraditch
Kind of a big deal
Kind of a big deal

That's what the guide is having you do when you setup the Application in Entra. You can use the application to restrict what groups/users are actually allowed to sign in.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
nicdc01
Getting noticed

Are you refering to to EA release of Access Manger? 
There are a couple new videos on the Meraki Minute Youtube channel that take you through the module as well as setting it up for your MR Devices and MS devices.

Configuration guides are here:
https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides

More detailed guide below:
https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_U...

 


  • Configure endpoints for username and password authentication
  • Configure Entra ID integration to synchronize users, user groups and user attributes
  • Configure SSIDs and Switches to use Access Manager
  • Configure authorizations to be used – SGTs, VLANs, Group Policies and others 
  • Configure Access Manager rules for policy evaluation
Get notified when there are additional replies to this discussion.