AnyConnect VPN

Sean Byrne 86 Reputation points
2022-09-19T17:55:16.77+00:00

hello
I am using Cisco AnyConnect on a aVPN to pass authentication to the Azure AD

I have configured the SAML strings

please see attached for failure message 242520-aad-failure.png

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,559 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Sean Byrne 86 Reputation points
    2022-09-19T19:32:46.86+00:00

    hello
    we configured the idp string and url login & logout on under the webvpn configuration

    we configured the idp string under the tunnel group

    from what I understand the customer has input the tunnel group name and base url on the AD configuration

    0 comments No comments

  2. Givary-MSFT 28,321 Reputation points Microsoft Employee
    2022-09-20T08:57:28.33+00:00

    @Sean Byrne

    Thank you for reaching out to us. As I understand you are trying to configure AnyConnect VPN with Azure AD, during the process you got this error AADSTS700016.

    AADSTS700016 - This means the application you are trying to access does not exist in the organization you are signing into or I would say the AppId of the application (sent as client_id) sent to Azure AD is not valid. Double check this is the correct AppId.

    AppId is not the same as the Applications Object ID, Service Principal or also called Enterprise Apps Object ID.

    saml idp [entityID] configuration under the ASA's webvpn configuration does not match the IdP Entity ID found in the Azure AD metadata.

    Let me know if you have any further questions.


  3. Sean Byrne 86 Reputation points
    2022-09-28T14:19:18.537+00:00

    sorry for the delay --the customer is still testing

    thanks for all your help

    I will update you with the results of the testing

    0 comments No comments