<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access Authentication with Certificate and Group Membership Retrieval in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260594#M44073</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer challenged me with the following problem:&lt;/P&gt;&lt;P&gt;If Personal Certificate is used as Authentication Method for Remote Access and my User Identity Store is Entra how do I get the&amp;nbsp;Group Membership Retrieval for "Offer Office Mode to group" option?&lt;/P&gt;&lt;P&gt;Does it always have to be an LDAP query from the Gateway to an On Prem Device for group membership when Personal Certificate is used as a login option?&lt;/P&gt;&lt;P&gt;If yes, is there something which forwards this LDAP query from On Prem to Entra?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody have a hint for me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
    <pubDate>Wed, 22 Oct 2025 16:12:59 GMT</pubDate>
    <dc:creator>C_H</dc:creator>
    <dc:date>2025-10-22T16:12:59Z</dc:date>
    <item>
      <title>Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260594#M44073</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer challenged me with the following problem:&lt;/P&gt;&lt;P&gt;If Personal Certificate is used as Authentication Method for Remote Access and my User Identity Store is Entra how do I get the&amp;nbsp;Group Membership Retrieval for "Offer Office Mode to group" option?&lt;/P&gt;&lt;P&gt;Does it always have to be an LDAP query from the Gateway to an On Prem Device for group membership when Personal Certificate is used as a login option?&lt;/P&gt;&lt;P&gt;If yes, is there something which forwards this LDAP query from On Prem to Entra?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody have a hint for me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 16:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260594#M44073</guid>
      <dc:creator>C_H</dc:creator>
      <dc:date>2025-10-22T16:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260644#M44080</link>
      <description>&lt;P&gt;The necessary groups are sent as part of the SAML Assertion, which is configured on the Entra ID side.&lt;BR /&gt;There is also configuration needed on the Check Point side (the creation of EXT_ID_ objects).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk177267" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177267&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 00:52:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260644#M44080</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-23T00:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260664#M44083</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Yes, I know this. But with Personal Certificate there is no SAML Mechanism triggered, since the certificate is presented by the client to the checkpoint and is then checked (is it valid? does the Check Point GW trust the Issuer? etc.). So there is no SAML ongoing in this case.&lt;/P&gt;&lt;P&gt;From my point of view it is not possible to do the Certificate Authentcation with SAML, so you have to relay on Personal Certificate as Login Option.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 06:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260664#M44083</guid>
      <dc:creator>C_H</dc:creator>
      <dc:date>2025-10-23T06:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260756#M44106</link>
      <description>&lt;P&gt;You're correct.&lt;BR /&gt;This is mentioned&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm?Highlight=SAML%20support" target="_self"&gt;in the documentation&lt;/A&gt;&amp;nbsp;under Known Limitations:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;SAML authentication cannot be configured with more authentication factors in the same login option. The Machine Certificate Authentication option is supported. To use Multiple Factor Authentication, configure the external Identity Provider to have multiple verification steps. The complexity and number of verification activities depends on the configuration of the Identity Provider.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 01:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260756#M44106</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-24T01:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260776#M44114</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;Can I ask why this is marked as solution for my questions?&lt;/P&gt;&lt;P&gt;From your answer the only thing confirmed is that SAML can't be used with other login options.&lt;/P&gt;&lt;P&gt;My initial problem (how to get group membership from entra if personal certificate as login option is used) was not solved by that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 06:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260776#M44114</guid>
      <dc:creator>C_H</dc:creator>
      <dc:date>2025-10-24T06:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260825#M44125</link>
      <description>&lt;P&gt;Is this certificate used to authenticate with Entra ID directly?&lt;BR /&gt;If so, we do not get involved in this.&lt;/P&gt;
&lt;P&gt;The SAML assertion, received as a result of successful authentication with Entra ID, tells us&amp;nbsp;you are authenticated and what groups you are actually authorized for.&lt;BR /&gt;The groups we recognize from SAML must be explicitly configured, as described in the SK/docs linked previously.&lt;BR /&gt;The groups passed to us are a function of configuration in Entra ID, with some information provided in the SK/docs linked previously.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 21:00:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/260825#M44125</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-24T21:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/261026#M44132</link>
      <description>&lt;P&gt;No, Entra is not in use, and I think that's where the misunderstanding comes from.&lt;/P&gt;&lt;P&gt;Authentication method is Personal Certificate, where user certificates are stored on the endpoints, the vpn clients present those certificates to the gateway and the gateway checks if the user certificates are valid and if the gateway trusts the CA (correct me please if anything is wrong in my understanding).&lt;/P&gt;&lt;P&gt;So everything is pretty much on prem handled. If the validation of the client certificate is successful one of the next steps is to check the group membership (if the corresponding settings are set in the RemoteAccess VPN Community or in the GW/Cluster Object --&amp;gt; Office Mode).&lt;/P&gt;&lt;P&gt;Now this is where the challenge starts: With on prem AD no problem, a LDAP Request is sent and the GW retrieves the Group membership for the user who is connecting. Now in my case, there is no on prem AD and the group membership info is in Entra ID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I get this group membership info to the checkpoint in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 12:52:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/261026#M44132</guid>
      <dc:creator>C_H</dc:creator>
      <dc:date>2025-10-27T12:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Authentication with Certificate and Group Membership Retrieval</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/261067#M44145</link>
      <description>&lt;P&gt;If you're using an on-premise method of authentication (personal certificates, in this case), you must use an on-premise method to gather the groups.&lt;BR /&gt;This is usually done via LDAP, but can also be done over RADIUS (assuming it's an authentication factor).&lt;BR /&gt;Not sure Entra provides these connectors at all.&lt;/P&gt;
&lt;P&gt;Otherwise, your only option to use SAML for authentication (where the groups are communicated via the SAML assertion).&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 18:53:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-Authentication-with-Certificate-and-Group/m-p/261067#M44145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-27T18:53:40Z</dc:date>
    </item>
  </channel>
</rss>

