New Microsoft Intune service for network access control

Published Jul 15 2021 08:31 AM 13.6K Views

Many Microsoft Intune customers use network access control (NAC) partner solutions to manage access to their on-premises resources. Our networking partners use the Intune NAC service to integrate Intune device compliance checks into their NAC solutions. This integration allows a NAC solution to receive a device’s enrollment and compliance state from Intune to manage access control.

 

In June, we released the Compliance Retrieval service. This service will replace the Intune NAC service, offering improved security and reliability for our customers. We are working with our partners to help transition existing NAC solutions to this new framework, and to ensure you receive the support you need.

 

What improvements does the Compliance Retrieval service include?

The new service includes changes to improve the security, reliability, and privacy of the NAC service. For example, it uses lookup by Intune device ID only, which removes the dependency on internal identifiers, such as serial numbers, which are not consistently accessible. It also eliminates MAC address identifiers, which are problematic because devices can have multiple or randomized MAC addresses. The new service is also streamlined to return only enrollment and compliance data from Intune. Any other device data not related to access control is eliminated from this service.

 

What do I need to do to accommodate the new service?

You must use certificate-based authentication for NAC-enabled networks with the new service. You will also need to include the Intune device ID in the subject alternative name (SAN) of your certificate profiles. To do this, add a Uniform Resource Identifier (URI) attribute with the format defined by your NAC provider, for example: IntuneDeviceId://{{DeviceID}}. For detailed instructions, see your VPN partner's documentation after they adopt the new service.

 

Each NAC partner is working with Intune on their own migration schedule and instructions, so timelines and specific instructions will vary based on product. Work directly with your NAC provider to understand what other changes are needed to accommodate the Compliance Retrieval service.

 

We’ll continue to update this post as our partners decide how to move forward with the Compliance Retrieval service.

 

Will the Compliance Retrieval service replace the original Intune NAC service?

Yes, we will stop supporting the Intune NAC service at the end of 2022. Our networking partners are working to move off the Intune NAC service. If you have questions about your specific use case, contact your NAC solution provider.

 

When do I need to transition to the new service? 

We will take down the original Intune NAC service at the end of 2022 to give our partners and customers time to transition to the Compliance Retrieval service and/or adopt the Microsoft Graph solution. Work with your NAC partner to determine what changes you need to make and when to maintain NAC availability.

 

How does this affect my users? 

Users should not notice any changes with the new service. However, if you don’t make the required modifications to your environment, it might affect user access to corporate resources on NAC-enabled networks. Work with your NAC partner to understand what changes are needed for your environment and get them implemented prior to the end of service for the Intune NAC Service.

 

We will continue to update this post as we continue to transition away from the Intune NAC service. If you have questions or comments for the Intune team, reply to this post or reach out to @IntuneSuppTeam on Twitter.

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-2544696%22%20slang%3D%22en-US%22%3ENew%20Microsoft%20Intune%20service%20for%20network%20access%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2544696%22%20slang%3D%22en-US%22%3E%3CP%3EMany%26nbsp%3BMicrosoft%20Intune%26nbsp%3Bcustomers%20use%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmem%2Fintune%2Fprotect%2Fnetwork-access-control-integrate%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Enetwork%20access%20control%20(NAC)%3C%2FA%3E%26nbsp%3Bpartner%20solutions%20to%20manage%20access%20to%20their%26nbsp%3Bon-premises%26nbsp%3Bresources.%26nbsp%3BOur%26nbsp%3Bnetworking%20partners%20use%20the%20Intune%20NAC%26nbsp%3Bservice%26nbsp%3Bto%20integrate%26nbsp%3BIntune%20device%26nbsp%3Bcompliance%26nbsp%3Bchecks%26nbsp%3Binto%26nbsp%3Btheir%20NAC%20solutions.%20This%20integration%26nbsp%3Ballows%26nbsp%3Ba%20NAC%20solution%26nbsp%3Bto%26nbsp%3Breceive%26nbsp%3Ba%26nbsp%3Bdevice%E2%80%99s%26nbsp%3Benrollment%20and%20compliance%20state%26nbsp%3Bfrom%26nbsp%3BIntune%20to%26nbsp%3Bmanage%26nbsp%3Baccess%20control.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20June%2C%26nbsp%3Bwe%20released%26nbsp%3Bthe%20Compliance%20Retrieval%20service.%20This%20service%26nbsp%3Bwill%26nbsp%3Breplace%20the%26nbsp%3BIntune%26nbsp%3BNAC%20service%2C%26nbsp%3Boffering%26nbsp%3Bimproved%20security%26nbsp%3Band%26nbsp%3Breliability%20for%20our%20customers.%26nbsp%3BWe%20are%20working%20with%20our%20partners%20to%20help%20transition%20existing%20NAC%20solutions%20to%20this%20new%20framework%2C%20and%20to%20ensure%26nbsp%3Byou%26nbsp%3Breceive%20the%20support%26nbsp%3Byou%20need.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EWhat%20improvements%20does%26nbsp%3Bthe%20Compliance%20Retrieval%26nbsp%3Bservice%26nbsp%3Binclude%3F%3CP%3EThe%20new%26nbsp%3Bservice%26nbsp%3Bincludes%20changes%20to%26nbsp%3Bimprove%26nbsp%3Bthe%20security%2C%20reliability%2C%20and%20privacy%20of%20the%20NAC%20service.%20For%20example%2C%20it%26nbsp%3Buses%26nbsp%3Blookup%20by%20Intune%20device%20ID%20only%2C%20which%26nbsp%3Bremoves%20the%20dependency%20on%20internal%20identifiers%2C%20such%20as%20serial%20numbers%2C%20which%20are%20not%20consistently%20accessible.%20It%20also%20eliminates%20MAC%20address%20identifiers%2C%20which%20are%20problematic%20because%20devices%20can%20have%20multiple%20or%20randomized%20MAC%20addresses.%26nbsp%3BThe%20new%20service%20is%20also%20streamlined%20to%20return%20only%20enrollment%20and%20compliance%20data%20from%20Intune.%26nbsp%3BAny%20other%20device%20data%20not%20related%20to%20access%20control%20is%20eliminated%20from%20this%20service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EWhat%20do%20I%20need%20to%20do%20to%20accommodate%20the%20new%26nbsp%3Bservice%3F%3CP%3EYou%26nbsp%3Bmust%26nbsp%3Buse%26nbsp%3Bcertificate-based%20authentication%26nbsp%3Bfor%20NAC-enabled%20networks%20with%20the%20new%20service.%26nbsp%3BYou%20will%20also%20need%20to%20include%26nbsp%3Bthe%20Intune%20device%20ID%20in%20the%20subject%20alternative%20name%26nbsp%3B(SAN)%26nbsp%3Bof%26nbsp%3Byour%26nbsp%3Bcertificate%20profiles.%26nbsp%3BTo%20do%20this%2C%20add%26nbsp%3Ba%26nbsp%3BUniform%20Resource%20Identifier%26nbsp%3B(URI)%20attribute%20with%20the%20format%26nbsp%3Bdefined%20by%20your%20NAC%20provider%2C%26nbsp%3Bfor%20example%3A%26nbsp%3BIntuneDeviceId%3A%2F%2F%7B%7BDeviceID%7D%7D.%26nbsp%3BFor%20detailed%20instructions%2C%26nbsp%3Bsee%20your%20VPN%20partner's%20documentation%20after%20they%20adopt%20the%20new%20service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEach%20NAC%20partner%20is%20working%20with%20Intune%20on%20their%20own%20migration%20schedule%20and%20instructions%2C%20so%20timelines%20and%20specific%20instructions%20will%20vary%26nbsp%3Bbased%20on%20product.%20Work%20directly%20with%20your%20NAC%20provider%26nbsp%3Bto%26nbsp%3Bunderstand%20what%20other%20changes%20are%20needed%20to%20accommodate%20the%20Compliance%20Retrieval%20service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%E2%80%99ll%20continue%20to%20update%20this%20post%20as%20our%20partners%20decide%20how%20to%20move%20forward%20with%20the%20Compliance%20Retrieval%20service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EWill%20the%20Compliance%20Retrieval%20service%20replace%20the%20original%20Intune%20NAC%20service%3F%3CP%3EYes%2C%20we%20will%20stop%20supporting%20the%20Intune%20NAC%20service%20at%20the%20end%20of%202022.%20Our%20networking%20partners%20are%20working%20to%20move%20off%20the%20Intune%20NAC%20service.%20If%20you%20have%20questions%20about%20your%20specific%20use%20case%2C%20contact%20your%20NAC%20solution%20provider.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EWhen%20do%20I%20need%20to%20transition%20to%20the%20new%20service%3F%26nbsp%3B%3CP%3EWe%20will%20take%20down%20the%20original%20Intune%20NAC%20service%20at%20the%20end%20of%202022%20to%20give%20our%20partners%20and%20customers%20time%20to%20transition%20to%20the%20Compliance%20Retrieval%20service%20and%2For%20adopt%20the%20Microsoft%20Graph%20solution.%20Work%20with%20your%20NAC%20partner%20to%20determine%20what%20changes%20you%20need%20to%20make%20and%20when%20to%20maintain%20NAC%20availability.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EHow%20does%20this%20affect%20my%20users%3F%26nbsp%3B%3CP%3EUsers%20should%20not%20notice%20any%20changes%20with%20the%20new%20service.%20However%2C%20if%20you%20don%E2%80%99t%20make%20the%20required%20modifications%20to%20your%20environment%2C%20it%20might%20affect%20user%20access%20to%20corporate%20resources%20on%20NAC-enabled%20networks.%20Work%20with%20your%20NAC%20partner%20to%20understand%20what%20changes%20are%20needed%20for%20your%20environment%20and%20get%20them%20implemented%20prior%20to%20the%20end%20of%20service%20for%20the%20Intune%20NAC%20Service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20will%26nbsp%3Bcontinue%20to%20update%20this%20post%20as%20we%26nbsp%3Bcontinue%20to%20transition%26nbsp%3Baway%26nbsp%3Bfrom%26nbsp%3Bthe%26nbsp%3BIntune%20NAC%20service.%20If%26nbsp%3Byou%20have%26nbsp%3Bquestions%20or%20comments%20for%20the%20Intune%20team%2C%20reply%20to%20this%20post%26nbsp%3Bor%20reach%20out%26nbsp%3Bto%E2%80%AF%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FIntuneSuppTeam%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3E%40IntuneSuppTeam%3C%2FA%3E%E2%80%AFon%20Twitter.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2544696%22%20slang%3D%22en-US%22%3E%3CP%3ERead%20this%20post%20to%20learn%20more%20about%20a%20new%20Microsoft%20Intune%20service%20for%20network%20access%20control!%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2544696%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Endpoint%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetwork%20access%20control%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3012710%22%20slang%3D%22ja-JP%22%3ERe%3A%20New%20Microsoft%20Intune%20service%20for%20network%20access%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3012710%22%20slang%3D%22ja-JP%22%3E%3CP%3EHi%2C%20is%20it%20possible%20to%20use%20the%20following%20third-party%20SCEP%20certificates%20for%20the%20certificate%20profile%20with%20the%20new%20NAC%20service%3F%26nbsp%3B%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fcertificate-authority-add-scep-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EUse%20third-party%20certification%20authorities%20(CA)%20with%20SCEP%20in%20Microsoft%20Intune%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Jul 15 2021 08:49 AM
Updated by: