<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN SAML Browser Authentication fails after latest Edge / Chrome updates in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264817#M1397</link>
    <description>&lt;P&gt;Correct - the GPO and Intune settings to resolve are in the links I posted.&amp;nbsp; We are pushing the setting using the Intune Settings Catalog for Edge.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Dec 2025 09:59:38 GMT</pubDate>
    <dc:creator>Ruan_Kotze</dc:creator>
    <dc:date>2025-12-09T09:59:38Z</dc:date>
    <item>
      <title>VPN SAML Browser Authentication fails after latest Edge / Chrome updates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264799#M1395</link>
      <description>&lt;P&gt;I have not seen any posts on this, so just a heads up.&lt;/P&gt;
&lt;P&gt;If users update to the latest Edge / Chrome / Chromium build they will receive a pop-up asking them to Allow access from your VPN url to the local network. Failing to do so will cause SAML authentication to fail.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32364i0E09D6651AE1C6EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN.png" alt="VPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorRuan_Kotze_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Microsoft References:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel" target="_blank" rel="noopener"&gt;Microsoft Edge release notes for Stable Channel | Microsoft Learn&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.microsoft.com/en-us/topic/control-a-website-s-access-to-the-local-network-in-microsoft-edge-ef7eff4c-676d-4105-935c-2acbcd841d51" target="_blank" rel="noopener"&gt;Control a website’s access to the local network in Microsoft Edge - Microsoft Support&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/localnetworkaccessallowedforurls" target="_blank" rel="noopener"&gt;Microsoft Edge Browser Policy Documentation LocalNetworkAccessAllowedForUrls | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Edit:&lt;BR /&gt;As per links above you can add the sites to the allow list via either GPO or Intune Settings Catalog for Edge.&lt;/P&gt;
&lt;P&gt;-Ruan&lt;/P&gt;
&lt;DIV id="tinyMceEditorRuan_Kotze_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorRuan_Kotze_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorRuan_Kotze_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 09:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264799#M1395</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-12-09T09:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SAML Browser Authentication fails after latest Edge / Chrome updates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264812#M1396</link>
      <description>&lt;P&gt;You can deploy that via GPO&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/localnetworkaccessallowedforurls" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/localnetworkaccessallowedforurls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We're still working on the fix, I can update details, later.&lt;/P&gt;&lt;P&gt;Workaround: Egde settings =&amp;gt; website permissions =&amp;gt; all permissions =&amp;gt; local network access =&amp;gt; add website&lt;/P&gt;&lt;P&gt;something like that, in german, its&amp;nbsp;Datenschutz, Suche und Dienste&lt;SPAN class=""&gt;/&lt;/SPAN&gt;Websiteberechtigungen&lt;SPAN class=""&gt;/&lt;/SPAN&gt;Alle Berechtigungen&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;Lokaler Netzwerkzugriff&lt;/SPAN&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;#########edit -&amp;nbsp;This is, what we did:&lt;/P&gt;&lt;P&gt;1. Quickfix on all computers that are not reachable by GPO: Go to Edge:&amp;nbsp;&lt;/P&gt;&lt;P&gt;edge://settings/privacy/sitePermissions/allPermissions/localNetworkAccess&lt;/P&gt;&lt;P&gt;and add your SAML-URL to allowed websites&lt;/P&gt;&lt;P&gt;(there may be way to do that smarter by reg or powershell, we just sent out a onepager with a screenshot)&lt;/P&gt;&lt;P&gt;2. (update MS-Edge ADMX templates from&amp;nbsp;&lt;A href="https://www.microsoft.com/de-de/edge/business/download" target="_blank"&gt;https://www.microsoft.com/de-de/edge/business/download&lt;/A&gt; and)&lt;/P&gt;&lt;P&gt;configure your MS-Edge-GPO with your SAML URL:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Administrative Templates/Microsoft Edge/Network settings/LocalNetworkAccessAllowedForUrls&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;to catch all computers, that are not working remotely.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 10:04:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264812#M1396</guid>
      <dc:creator>bsc</dc:creator>
      <dc:date>2025-12-09T10:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SAML Browser Authentication fails after latest Edge / Chrome updates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264817#M1397</link>
      <description>&lt;P&gt;Correct - the GPO and Intune settings to resolve are in the links I posted.&amp;nbsp; We are pushing the setting using the Intune Settings Catalog for Edge.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 09:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/264817#M1397</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-12-09T09:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SAML Browser Authentication fails after latest Edge / Chrome updates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/265490#M1398</link>
      <description>&lt;P&gt;My customer and I have also recently encountered this permission prompt. The customer is confused about why the prompt still appears even though a public certificate has already been imported into the Remote Access Web Portal via SmartConsole. Could this be a firewall-related issue?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 03:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/265490#M1398</guid>
      <dc:creator>Vanness_Chen</dc:creator>
      <dc:date>2025-12-17T03:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SAML Browser Authentication fails after latest Edge / Chrome updates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/265553#M1399</link>
      <description>&lt;P&gt;This is a security feature of the underlying web browser and has nothing to do with certificates.&lt;BR /&gt;MacOS also prompts me with a similar message periodically for various apps (including Chrome).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 15:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-SAML-Browser-Authentication-fails-after-latest-Edge-Chrome/m-p/265553#M1399</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-17T15:57:26Z</dc:date>
    </item>
  </channel>
</rss>

