<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Simplifying Zero Trust Security with Infinity Identity: Video, Slides, and Q&amp;amp;A in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Simplifying-Zero-Trust-Security-with-Infinity-Identity-Video/m-p/231275#M44559</link>
    <description>&lt;P&gt;Slides are posted below the Q&amp;amp;A, which is posted below the video:&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6364002812112w1290h540r489" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6364002812112" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6364002812112w1290h540r489');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6364002812112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;H3&gt;Is this working with Quantum Spark SMB Gateways?&lt;/H3&gt;
&lt;P&gt;Not currently.&lt;/P&gt;
&lt;H3&gt;Is it a full IdP solution?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is for integrating with Identity Provider solutions. It is not an Identity Provider on its own.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Any UEBA features included?&lt;/H3&gt;
&lt;P&gt;We plan to integrate this information provided through the Identity Provider in the future.&lt;/P&gt;
&lt;H3&gt;What are the requirements to use Infinity Identity?&lt;/H3&gt;
&lt;P&gt;During the Early Availability phase:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;R82 Management&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;R81.20 JHF 65 Gateways&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We will integrate support into future JHF&lt;/P&gt;
&lt;H3&gt;Does the new captive portal support multiple authentication methods, where the user can choose?&lt;/H3&gt;
&lt;P&gt;This will be possible in the near future.&lt;/P&gt;
&lt;H3&gt;Infinity Identity require any additional licenses???&lt;/H3&gt;
&lt;P&gt;No cost during EA phase. Cost (if any) is still under discussion.&lt;/P&gt;
&lt;P&gt;live answered&lt;/P&gt;
&lt;H3&gt;Will be same "seamless integration" available for Cisco ISE?&lt;/H3&gt;
&lt;P&gt;Not initially. We're looking to integrate additional source of identity. If you have specific requests in this area, please reach out to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;.&lt;/P&gt;
&lt;H3&gt;Will there still be a need for the Identity Agent? How will identities be captured on the macOS side with the Identity Agent?&lt;/H3&gt;
&lt;P&gt;For Microsoft Intune and/or Windows Defender, we can integrate without a specific agent. In other cases, Identity Agents will still be needed.&lt;/P&gt;
&lt;P&gt;Note that Harmony Endpoint and Harmony SASE will be supported as an identity source in the future.&lt;/P&gt;
&lt;H3&gt;Are these IdPs exclusive to Infinity Identity? Will it come for on-prem environment?&lt;/H3&gt;
&lt;P&gt;The IdPs should also work for entirely on-premise environments, however the level of integration will be significantly improved using Infinity Identity.&lt;/P&gt;
&lt;H3&gt;Is there a specific integration with Entra ID, like user object score check if a user score below 80, do not give access through the firewall rulebase?&lt;/H3&gt;
&lt;P&gt;This is planned.&lt;/P&gt;
&lt;H3&gt;Are multiple Entra-ID tenants are supported?&lt;/H3&gt;
&lt;P&gt;Yes&lt;/P&gt;
&lt;H3&gt;Will identity information from the Identity Infinity be available via API?&lt;/H3&gt;
&lt;P&gt;Not currently. The Identity Awareness API currently queries pdp, whereas Infinity Identity talks directly to pep.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;How does Infinity Identity acquire identities from Intune/Defender clients?&lt;/H3&gt;
&lt;P&gt;Though a management-side integration (i.e. it's not exposed on the client).&lt;/P&gt;
&lt;H3&gt;How will be the transition from classical AzureAD integration to Infinity ID occur?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is another identity source that can be used alongside your existing methods.&lt;/P&gt;
&lt;H3&gt;How many (concurrent) users are supported during EA?&lt;/H3&gt;
&lt;P&gt;The limiting factor is the number of identities a single gateway can support (200,000).&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Can the solution cope with dual stack IPv4 and IPv6?&lt;/H3&gt;
&lt;P&gt;This is planned.&lt;/P&gt;
&lt;H3&gt;Is connectivity from Infinity Portal to on prem AD handled via inext-agent (nano)?&lt;/H3&gt;
&lt;P&gt;Yes&lt;/P&gt;
&lt;H3&gt;Is group membership cached or is checked for every packet?&lt;/H3&gt;
&lt;P&gt;Cached. However, we periodically update the group information from the IdP (either poll or push depending on configuration).&lt;/P&gt;
&lt;H3&gt;Is this supported on Smart-1 Cloud?&lt;/H3&gt;
&lt;P&gt;One tenants are upgrade to R82, this should be supported.&lt;/P&gt;
&lt;H3&gt;Is there an on-premise Infinity Identity server planned in the future or only in the cloud?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is hosted in Infinity Portal. The IdPs supported (outside of on-prem AD) are in the cloud already.&lt;/P&gt;
&lt;H3&gt;Could you use machine objects (in the access roles) or only users with EntraID/Intune integration?&lt;/H3&gt;
&lt;P&gt;Yes, these should be included.&lt;/P&gt;
&lt;H3&gt;Can i add IDP that are not in the default list?&lt;/H3&gt;
&lt;P&gt;There is an option to configure Generic SAML. However, you will not get the group information from Generic SAML.&lt;/P&gt;
&lt;H3&gt;How can I participate in the Early Availability for Infinity Identity?&lt;/H3&gt;
&lt;P&gt;Reach out to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;(&lt;A href="mailto:royip@checkpoint.com" target="_blank" rel="noopener"&gt;royip@checkpoint.com&lt;/A&gt;)&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 22:09:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-30T22:09:11Z</dc:date>
    <item>
      <title>Simplifying Zero Trust Security with Infinity Identity: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Simplifying-Zero-Trust-Security-with-Infinity-Identity-Video/m-p/231275#M44559</link>
      <description>&lt;P&gt;Slides are posted below the Q&amp;amp;A, which is posted below the video:&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6364002812112w1290h540r587" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6364002812112" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6364002812112w1290h540r587');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6364002812112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;H3&gt;Is this working with Quantum Spark SMB Gateways?&lt;/H3&gt;
&lt;P&gt;Not currently.&lt;/P&gt;
&lt;H3&gt;Is it a full IdP solution?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is for integrating with Identity Provider solutions. It is not an Identity Provider on its own.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Any UEBA features included?&lt;/H3&gt;
&lt;P&gt;We plan to integrate this information provided through the Identity Provider in the future.&lt;/P&gt;
&lt;H3&gt;What are the requirements to use Infinity Identity?&lt;/H3&gt;
&lt;P&gt;During the Early Availability phase:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;R82 Management&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;R81.20 JHF 65 Gateways&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We will integrate support into future JHF&lt;/P&gt;
&lt;H3&gt;Does the new captive portal support multiple authentication methods, where the user can choose?&lt;/H3&gt;
&lt;P&gt;This will be possible in the near future.&lt;/P&gt;
&lt;H3&gt;Infinity Identity require any additional licenses???&lt;/H3&gt;
&lt;P&gt;No cost during EA phase. Cost (if any) is still under discussion.&lt;/P&gt;
&lt;P&gt;live answered&lt;/P&gt;
&lt;H3&gt;Will be same "seamless integration" available for Cisco ISE?&lt;/H3&gt;
&lt;P&gt;Not initially. We're looking to integrate additional source of identity. If you have specific requests in this area, please reach out to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;.&lt;/P&gt;
&lt;H3&gt;Will there still be a need for the Identity Agent? How will identities be captured on the macOS side with the Identity Agent?&lt;/H3&gt;
&lt;P&gt;For Microsoft Intune and/or Windows Defender, we can integrate without a specific agent. In other cases, Identity Agents will still be needed.&lt;/P&gt;
&lt;P&gt;Note that Harmony Endpoint and Harmony SASE will be supported as an identity source in the future.&lt;/P&gt;
&lt;H3&gt;Are these IdPs exclusive to Infinity Identity? Will it come for on-prem environment?&lt;/H3&gt;
&lt;P&gt;The IdPs should also work for entirely on-premise environments, however the level of integration will be significantly improved using Infinity Identity.&lt;/P&gt;
&lt;H3&gt;Is there a specific integration with Entra ID, like user object score check if a user score below 80, do not give access through the firewall rulebase?&lt;/H3&gt;
&lt;P&gt;This is planned.&lt;/P&gt;
&lt;H3&gt;Are multiple Entra-ID tenants are supported?&lt;/H3&gt;
&lt;P&gt;Yes&lt;/P&gt;
&lt;H3&gt;Will identity information from the Identity Infinity be available via API?&lt;/H3&gt;
&lt;P&gt;Not currently. The Identity Awareness API currently queries pdp, whereas Infinity Identity talks directly to pep.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;How does Infinity Identity acquire identities from Intune/Defender clients?&lt;/H3&gt;
&lt;P&gt;Though a management-side integration (i.e. it's not exposed on the client).&lt;/P&gt;
&lt;H3&gt;How will be the transition from classical AzureAD integration to Infinity ID occur?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is another identity source that can be used alongside your existing methods.&lt;/P&gt;
&lt;H3&gt;How many (concurrent) users are supported during EA?&lt;/H3&gt;
&lt;P&gt;The limiting factor is the number of identities a single gateway can support (200,000).&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Can the solution cope with dual stack IPv4 and IPv6?&lt;/H3&gt;
&lt;P&gt;This is planned.&lt;/P&gt;
&lt;H3&gt;Is connectivity from Infinity Portal to on prem AD handled via inext-agent (nano)?&lt;/H3&gt;
&lt;P&gt;Yes&lt;/P&gt;
&lt;H3&gt;Is group membership cached or is checked for every packet?&lt;/H3&gt;
&lt;P&gt;Cached. However, we periodically update the group information from the IdP (either poll or push depending on configuration).&lt;/P&gt;
&lt;H3&gt;Is this supported on Smart-1 Cloud?&lt;/H3&gt;
&lt;P&gt;One tenants are upgrade to R82, this should be supported.&lt;/P&gt;
&lt;H3&gt;Is there an on-premise Infinity Identity server planned in the future or only in the cloud?&lt;/H3&gt;
&lt;P&gt;Infinity Identity is hosted in Infinity Portal. The IdPs supported (outside of on-prem AD) are in the cloud already.&lt;/P&gt;
&lt;H3&gt;Could you use machine objects (in the access roles) or only users with EntraID/Intune integration?&lt;/H3&gt;
&lt;P&gt;Yes, these should be included.&lt;/P&gt;
&lt;H3&gt;Can i add IDP that are not in the default list?&lt;/H3&gt;
&lt;P&gt;There is an option to configure Generic SAML. However, you will not get the group information from Generic SAML.&lt;/P&gt;
&lt;H3&gt;How can I participate in the Early Availability for Infinity Identity?&lt;/H3&gt;
&lt;P&gt;Reach out to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;(&lt;A href="mailto:royip@checkpoint.com" target="_blank" rel="noopener"&gt;royip@checkpoint.com&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 22:09:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Simplifying-Zero-Trust-Security-with-Infinity-Identity-Video/m-p/231275#M44559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-30T22:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Simplifying Zero Trust Security with Infinity Identity: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Simplifying-Zero-Trust-Security-with-Infinity-Identity-Video/m-p/231330#M44587</link>
      <description>&lt;P&gt;Thanks for this exciting opportunity to share Infinity Identity.&lt;/P&gt;
&lt;P&gt;To join our EA program or if you have any additional questions, don't hesitate to contact me.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 08:38:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Simplifying-Zero-Trust-Security-with-Infinity-Identity-Video/m-p/231330#M44587</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2024-10-31T08:38:07Z</dc:date>
    </item>
  </channel>
</rss>

