<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: windows identity agent with entra groups for authorization in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/283045#M47186</link>
    <description>&lt;P&gt;Thanks for tagging me.&lt;/P&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4495"&gt;@dave_vz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;An alternative solution would be &lt;A href="https://www.checkpoint.com/resources/items/solution-brief-check-point-identity-and-trust" target="_self"&gt;Identity and Trust&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;It leverages already existing clients such as Microsoft Intune, Microsoft Defender, CrowdStrike Falcon, and also Check Point products such as SASE, Workforce AI, Endpoint, and Browser security. We fully support Entra ID and also other IDPs.&lt;/P&gt;
&lt;P&gt;If you want to get more information, feel free to DM / tag me&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2026 05:32:46 GMT</pubDate>
    <dc:creator>Royi_Priov</dc:creator>
    <dc:date>2026-09-30T05:32:46Z</dc:date>
    <item>
      <title>windows identity agent with entra groups for authorization</title>
      <link>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/282817#M47131</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a question.&lt;/P&gt;&lt;P&gt;we are using identity agent on windows with sso towards the ad domain.&lt;/P&gt;&lt;P&gt;this works ok.&lt;/P&gt;&lt;P&gt;we can create access roles that reference ad groups and this also works&lt;/P&gt;&lt;P&gt;we are also using entra.&lt;/P&gt;&lt;P&gt;i would like to know if i can mix them together&lt;/P&gt;&lt;P&gt;so get the identity of the user via the identity agent on the pc (this works)&lt;/P&gt;&lt;P&gt;and match this with a entra group to deliver the authorization.&lt;/P&gt;&lt;P&gt;i configured entra with succes, but in my testing i see no match happening between this combination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 08:24:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/282817#M47131</guid>
      <dc:creator>dave_vz</dc:creator>
      <dc:date>2026-09-25T08:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: windows identity agent with entra groups for authorization</title>
      <link>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/282873#M47139</link>
      <description>&lt;P&gt;Groups in LDAP (for on-premise AD) versus groups in SAML (i.e. Entra ID) are handled and represented differently.&lt;BR /&gt;As a result, there is no way to correlate between the two.&lt;/P&gt;
&lt;P&gt;Entra ID groups (passed to the gateway via the SAML assertion) can be used in policies, but they must be explicitly defined.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk177267" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177267&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having said that,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;is this something that Identity and Trust allows for?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 19:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/282873#M47139</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-25T19:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: windows identity agent with entra groups for authorization</title>
      <link>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/283045#M47186</link>
      <description>&lt;P&gt;Thanks for tagging me.&lt;/P&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4495"&gt;@dave_vz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;An alternative solution would be &lt;A href="https://www.checkpoint.com/resources/items/solution-brief-check-point-identity-and-trust" target="_self"&gt;Identity and Trust&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;It leverages already existing clients such as Microsoft Intune, Microsoft Defender, CrowdStrike Falcon, and also Check Point products such as SASE, Workforce AI, Endpoint, and Browser security. We fully support Entra ID and also other IDPs.&lt;/P&gt;
&lt;P&gt;If you want to get more information, feel free to DM / tag me&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2026 05:32:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/windows-identity-agent-with-entra-groups-for-authorization/m-p/283045#M47186</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2026-09-30T05:32:46Z</dc:date>
    </item>
  </channel>
</rss>

