<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215234#M8757</link>
    <description>&lt;P&gt;Below is a description of the relevant functionality as supported on Harmony Endpoint&lt;/P&gt;
&lt;P&gt;1) From which release is support for Microsoft Entra ID be available? Windows Client Release E88.00&lt;/P&gt;
&lt;P&gt;2) Are there related management changes for this support?&lt;/P&gt;
&lt;P&gt;Yes. There is an additional AD scanner type that needs to be defined. This will be available on cloud management at time of E88.00 release&lt;/P&gt;
&lt;P&gt;Schedule for on-premise management availability to be confirmed&lt;/P&gt;
&lt;P&gt;A sample of the new AD scanner definitions can be seen in the attached powerpoint&lt;/P&gt;
&lt;P&gt;3) Some related implementation aspects&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Once connected to Entra ID the following operations can be performed&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;You can import devices, groups, users, and administrative units from Azure Active Directory to Harmony Endpoint Management&lt;/LI&gt;
&lt;LI&gt;Any imported objects appear in Asset Management&amp;gt; Organization Tree &amp;gt; Directories -&amp;gt; Azure Directory&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;For a deployment where both On-prem AD and Entra ID are configured the data from the on-prem AD is given the highest priority&lt;/LI&gt;
&lt;LI&gt;Multiple Azure AD directories can be defined on Harmony Endpoint management. Device information is taken from where the client is joined&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;4) Are there any functional limitations with this support&lt;/P&gt;
&lt;P&gt;&lt;U&gt;4.1 Hybrid Mode&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;When working in hybrid mode, there is a both an on-premise AD and Entra ID cloud based component. Data may be synchronized between the two&lt;/P&gt;
&lt;P&gt;For hybrid mode two corresponding scanners need defined on HEP management for the on-premise and cloud based components&lt;/P&gt;
&lt;P&gt;This enables full client functionality in this configuration&lt;/P&gt;
&lt;P&gt;&lt;U&gt;4.2 Standalone / Cloud Only &lt;/U&gt;&lt;/P&gt;
&lt;P&gt;When moving from on-prem to cloud based AD many authentication related aspects are changing and this can cause issues across some capabilities&lt;/P&gt;
&lt;P&gt;In such a configuration there are caveats on the following functionality&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use of Smart Cards together with MEPP package&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;These are not currently supported&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Mac clients&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Mac Clients with Entra ID support is not supported currently by Microsoft. Microsoft is providing additional capabilities to allow this. We will look to align when becomes available&lt;/LI&gt;
&lt;LI&gt;Mac Clients can be used in this configuration when working with Intune. Related configuration for this option is outside scope of Harmony endpoint support&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Issues with password change for FDE&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;In pure Entra ID environments (only) a password change cannot be intercepted by the credential provider.&lt;/LI&gt;
&lt;LI&gt;This leads to a limitation that the end user must lock their screen after changing a password for the password change to take effect in FDE/preboot&lt;/LI&gt;
&lt;LI&gt;Without lock screen preboot password is not synced with Windows password. This means that the old password will be in effect in preboot and potentially could cause a locked user.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;</description>
    <pubDate>Sun, 26 May 2024 06:56:07 GMT</pubDate>
    <dc:creator>JonnyRabinowitz</dc:creator>
    <dc:date>2024-05-26T06:56:07Z</dc:date>
    <item>
      <title>Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215176#M8747</link>
      <description>&lt;P&gt;Hey All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a couple of customers, who are slowly moving towards Entra ID over On-Prem AD. And that also means joinning machines to Entra and authenticating against Entra...&lt;/P&gt;&lt;P&gt;The result is that users &amp;amp; Machines that are not using on-prem AD, does not get the correct policies applied &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone found a way to correct this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 11:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215176#M8747</guid>
      <dc:creator>rasmuswiegman</dc:creator>
      <dc:date>2024-05-24T11:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215234#M8757</link>
      <description>&lt;P&gt;Below is a description of the relevant functionality as supported on Harmony Endpoint&lt;/P&gt;
&lt;P&gt;1) From which release is support for Microsoft Entra ID be available? Windows Client Release E88.00&lt;/P&gt;
&lt;P&gt;2) Are there related management changes for this support?&lt;/P&gt;
&lt;P&gt;Yes. There is an additional AD scanner type that needs to be defined. This will be available on cloud management at time of E88.00 release&lt;/P&gt;
&lt;P&gt;Schedule for on-premise management availability to be confirmed&lt;/P&gt;
&lt;P&gt;A sample of the new AD scanner definitions can be seen in the attached powerpoint&lt;/P&gt;
&lt;P&gt;3) Some related implementation aspects&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Once connected to Entra ID the following operations can be performed&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;You can import devices, groups, users, and administrative units from Azure Active Directory to Harmony Endpoint Management&lt;/LI&gt;
&lt;LI&gt;Any imported objects appear in Asset Management&amp;gt; Organization Tree &amp;gt; Directories -&amp;gt; Azure Directory&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;For a deployment where both On-prem AD and Entra ID are configured the data from the on-prem AD is given the highest priority&lt;/LI&gt;
&lt;LI&gt;Multiple Azure AD directories can be defined on Harmony Endpoint management. Device information is taken from where the client is joined&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;4) Are there any functional limitations with this support&lt;/P&gt;
&lt;P&gt;&lt;U&gt;4.1 Hybrid Mode&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;When working in hybrid mode, there is a both an on-premise AD and Entra ID cloud based component. Data may be synchronized between the two&lt;/P&gt;
&lt;P&gt;For hybrid mode two corresponding scanners need defined on HEP management for the on-premise and cloud based components&lt;/P&gt;
&lt;P&gt;This enables full client functionality in this configuration&lt;/P&gt;
&lt;P&gt;&lt;U&gt;4.2 Standalone / Cloud Only &lt;/U&gt;&lt;/P&gt;
&lt;P&gt;When moving from on-prem to cloud based AD many authentication related aspects are changing and this can cause issues across some capabilities&lt;/P&gt;
&lt;P&gt;In such a configuration there are caveats on the following functionality&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use of Smart Cards together with MEPP package&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;These are not currently supported&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Mac clients&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Mac Clients with Entra ID support is not supported currently by Microsoft. Microsoft is providing additional capabilities to allow this. We will look to align when becomes available&lt;/LI&gt;
&lt;LI&gt;Mac Clients can be used in this configuration when working with Intune. Related configuration for this option is outside scope of Harmony endpoint support&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Issues with password change for FDE&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;In pure Entra ID environments (only) a password change cannot be intercepted by the credential provider.&lt;/LI&gt;
&lt;LI&gt;This leads to a limitation that the end user must lock their screen after changing a password for the password change to take effect in FDE/preboot&lt;/LI&gt;
&lt;LI&gt;Without lock screen preboot password is not synced with Windows password. This means that the old password will be in effect in preboot and potentially could cause a locked user.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 26 May 2024 06:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215234#M8757</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-05-26T06:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215275#M8758</link>
      <description>&lt;P&gt;Hi Jonny,&lt;/P&gt;&lt;P&gt;Thanks a lot! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, the E88 has been realeased a while ago, and I don't see the "Add Azure AD Scanner" anywhere &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; Is there anything that should be enabled before getting this?&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 06:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215275#M8758</guid>
      <dc:creator>rasmuswiegman</dc:creator>
      <dc:date>2024-05-27T06:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215278#M8759</link>
      <description>&lt;P&gt;If you do not see the option on the cloud management then please send me the tenant ID and version (can unicast) and may need to schedule upgrade for the management&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 06:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215278#M8759</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-05-27T06:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215280#M8761</link>
      <description>&lt;P&gt;This is where option should be&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 07:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/215280#M8761</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-05-27T07:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222339#M9059</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I also don't see the entra-id option in my tenant and a customer has the same issue. Is this not available across the board or is it done on a case by case basis?&lt;/P&gt;&lt;P&gt;Is it limited by Checkpoint or MS licensing?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 08:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222339#M9059</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-07-31T08:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222346#M9060</link>
      <description>&lt;P&gt;Hi. I assume you have a cloud based tenant&lt;/P&gt;
&lt;P&gt;Is not related to licensing but more dependent on upgrade cycle for your tenant. If wan to unicast your tenant details to me I can check schedule on updates&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 09:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222346#M9060</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-07-31T09:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222375#M9062</link>
      <description>&lt;P&gt;thanks - mine is a dev tenant as a partner, so not uber critical (thanks for the offer though) - however will all tenants be upgraded in time? appreciate the response!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 13:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222375#M9062</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-07-31T13:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone succesfully used Entra-ID accounts/groups in Harmny Endpoint rules?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222376#M9063</link>
      <description>&lt;P&gt;Yes. Over time all tenants get upgraded to latest. I do not know the cycle time by which all tenants are upgraded&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 13:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Has-anyone-succesfully-used-Entra-ID-accounts-groups-in-Harmny/m-p/222376#M9063</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-07-31T13:38:24Z</dc:date>
    </item>
  </channel>
</rss>

