<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness using Azure AD in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93340#M11289</link>
    <description>&lt;P&gt;VPN clients currently do not support SAML authentication.&lt;BR /&gt;This is planned for a later release.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 19:48:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-04T19:48:14Z</dc:date>
    <item>
      <title>Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/84940#M11280</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Possibly a daft question, but can anyone confirm if IA works against Azure AD as opposed to 'normal' AD? This is for an org that won't have any on prem AD at the end of the implementation.&lt;/P&gt;&lt;P&gt;I've had a look through the deployment guide for the version we would be implementing but it doesn't specifically mention Azure as being OK and I understand from our cloud architects that it's a bit different to AD as I know it.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;A.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 14:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/84940#M11280</guid>
      <dc:creator>adamhi</dc:creator>
      <dc:date>2020-05-12T14:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85011#M11281</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;this is still in EA, right?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 04:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85011#M11281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-13T04:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85014#M11282</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30910"&gt;@adamhi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In R80.40, you can use SAML integration with AzureAD for authentication and autorization.&lt;/P&gt;
&lt;P&gt;However, in the IDA picker (when you create access roles), you will need to represent the AzureAD objects (users/machines/groups) manually as "Identity Tag" objects.&lt;/P&gt;
&lt;P&gt;In R81, the integration of AzureAD in IDA picker will be available, where you can create your AzureAD object and select the objects from AAD same way as you do it on regular AD.&lt;/P&gt;
&lt;P&gt;It will be available for EA via R81 EA program. Please contact your local SE for more details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 05:55:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85014#M11282</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-05-13T05:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85105#M11283</link>
      <description>&lt;P&gt;Thanks gents, much appreciated.&lt;/P&gt;&lt;P&gt;This isn't going to be needed until Q2 2021, so I'm not sure we need to look into EA. I'll let the hierarchy know that it is feasible given current tech stack.&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 18:53:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85105#M11283</guid>
      <dc:creator>adamhi</dc:creator>
      <dc:date>2020-05-13T18:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85163#M11284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30910"&gt;@adamhi&lt;/a&gt;&amp;nbsp;, by that time you will be able to use the GA of this feature (as part of R81).&lt;/P&gt;
&lt;P&gt;Good luck &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 07:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/85163#M11284</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-05-14T07:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93170#M11285</link>
      <description>&lt;P&gt;Hi, just the manager needs to use the R80.40 to work with SAML? Or the gateways too?&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 15:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93170#M11285</guid>
      <dc:creator>Martins</dc:creator>
      <dc:date>2020-08-03T15:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93171#M11286</link>
      <description>&lt;P&gt;This requires R80.40+ gateways.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 15:16:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93171#M11286</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-03T15:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93258#M11287</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30227"&gt;@Martins&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will clarify:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In R80.40 we have added SAML support to IDA captive portal. it means we can use AAD as SAML Identity Provider.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;in R81 we have added AzureAD as user directory, which means you can configure entities (users/group/machines) from AAD in Identity Awareness Access Roles objects.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both features requires both SmartCenter and GW to be in this version.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 08:59:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93258#M11287</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-08-04T08:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93288#M11288</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Thank you for clarify.&lt;BR /&gt;Can I use SAML with 3rd party (MFA) as a Identity provider to autenticate the VPN ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 12:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93288#M11288</guid>
      <dc:creator>Martins</dc:creator>
      <dc:date>2020-08-04T12:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93340#M11289</link>
      <description>&lt;P&gt;VPN clients currently do not support SAML authentication.&lt;BR /&gt;This is planned for a later release.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 19:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/93340#M11289</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-04T19:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/100114#M11290</link>
      <description>&lt;P&gt;R81 IDA admin guide has two videos regarding SAML and Azure AD configuration. (The SAML video was available in R80.40 admin guide.)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Show-me-the-Videos.htm?tocpath=_____4" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Show-me-the-Videos.htm?tocpath=_____4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 06:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/100114#M11290</guid>
      <dc:creator>Paul_Grigg</dc:creator>
      <dc:date>2020-10-26T06:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/111774#M15465</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;- I went through the R81 Identity Awareness admin guide and watched the videos. It shows that it SAML is supported for Captive Portal. Will this also work for the Endpoint Security VPN clients?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 07:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/111774#M15465</guid>
      <dc:creator>AntoF</dc:creator>
      <dc:date>2021-02-25T07:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/111776#M15467</link>
      <description>&lt;P&gt;Just answered this in a different thread where you asked the same question: coming soon.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 07:18:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/111776#M15467</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-25T07:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113371#M15796</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;&lt;P&gt;I am trying to add my azure datacenter to checkpoint but the below message occurs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AZURE.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10953iA1C237DC35EE150D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AZURE.JPG" alt="AZURE.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems that checkpoint cannot establish a connection to azure. Yes i have create a custom app to azure.&lt;/P&gt;&lt;P&gt;Please help. I want to have IDA from Checkpoint to Azure AD.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:04:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113371#M15796</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2021-03-13T07:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113372#M15797</link>
      <description>&lt;P&gt;So…what does it say when you click for details?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113372#M15797</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-13T07:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113374#M15798</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sa.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10954iE943C165D690939B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sa.JPG" alt="sa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In which way checkpoint contacts azure?&lt;/P&gt;&lt;P&gt;Do i have to set a policy for this communication?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113374#M15798</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2021-03-13T07:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113375#M15799</link>
      <description>&lt;P&gt;I would assume so, yes.&lt;BR /&gt;It would be coming from your management in this case, I assume on port 443, to the relevant API endpoint in Azure.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113375#M15799</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-13T07:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113376#M15800</link>
      <description>&lt;P&gt;You mean the secure management server as a source and destination port 443 to where? can u make an example please?&lt;/P&gt;&lt;P&gt;I have already a rule from sms to everywhere.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:50:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113376#M15800</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2021-03-13T07:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113382#M15801</link>
      <description>&lt;P&gt;The traffic for specific node to azure is allowed and from the management server to internet. I don't understand why this connection fails.&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 09:45:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113382#M15801</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2021-03-13T09:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113391#M15802</link>
      <description>&lt;P&gt;Recommend a TAC case here unless&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;has other suggestions.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 17:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/113391#M15802</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-13T17:13:17Z</dc:date>
    </item>
  </channel>
</rss>

