<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPM and SAML with Entra ID in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264846#M1407</link>
    <description>&lt;P&gt;Do you see anything when you run pdp monitor user and then that username? If not, then thats your issue. However, if you do see results, maybe try disable rule, install policy-re-enable, install again, test.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Dec 2025 11:52:10 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-12-09T11:52:10Z</dc:date>
    <item>
      <title>Remote Access VPN and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264748#M1400</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have security gateway 9000 series with 81.20 version. Our users authenticating to remote access VPN via SAML (Entra ID).&lt;/P&gt;
&lt;P&gt;Auth works fine, but we facing problem with Access Roles and policies. I can see source user in logs but traffic didin't match to rule with access role where user account is present.&lt;/P&gt;
&lt;P&gt;We have policies with Access Role and in this object are user form Entra ID.&lt;/P&gt;
&lt;P&gt;In Entra we have two applications, first from gallery "Checkpoint Remote Secure Access VPN" for SAML auth, second custom APP used as Azure AD object in SMS.&lt;/P&gt;
&lt;P&gt;Main problem is situation where we have rule with access role and this access role have user account form Azure AD, but traffic from user didin't hit expected rule and goes to clean up rule.&lt;/P&gt;
&lt;P&gt;To integrate Remote Access VPN and Entra ID throught SAML we followed this video&amp;nbsp;&lt;SPAN&gt;&lt;A class="" title="https://www.youtube.com/watch?v=yzvb3sj3fz8" href="https://www.youtube.com/watch?v=yZVB3sJ3fZ8" target="_blank" rel="noreferrer noopener"&gt;https://www.youtube.com/watch?v=yZVB3sJ3fZ8&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We done almost everything form this post&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-and-EntraID-Group-Authorization/td-p/245325" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-and-EntraID-Group-Authorization/td-p/245325&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In one access role we have one user, but in feature we will be adding groups. In logs i can see source user in format &lt;A href="mailto:name@domain" target="_blank" rel="noopener"&gt;name@domain&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know what the potential problem could be ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 15:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264748#M1400</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T15:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264776#M1401</link>
      <description>&lt;P&gt;Are you able to attach a screenshot of the rule? Please blur out any sensitive data.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 01:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264776#M1401</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T01:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264790#M1402</link>
      <description>&lt;P&gt;Are you utilising on-prem AD as well or pure Entra?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 07:01:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264790#M1402</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-12-09T07:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264828#M1403</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;screenshots od rule and acces role is below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule.png" style="width: 949px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32370i954E09754E0408B3/image-dimensions/949x53?v=v2" width="949" height="53" role="button" title="Rule.png" alt="Rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Access_Role.png" style="width: 454px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32371i338EF182664D84D7/image-dimensions/454x359?v=v2" width="454" height="359" role="button" title="Access_Role.png" alt="Access_Role.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 10:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264828#M1403</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T10:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264829#M1404</link>
      <description>&lt;P&gt;Hi we using on-perm AD and Entra ID&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 10:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264829#M1404</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T10:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264842#M1405</link>
      <description>&lt;P&gt;Are there any hits on that rule at all?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 11:46:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264842#M1405</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T11:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264845#M1406</link>
      <description>&lt;P&gt;Not now, hits was when i don't have access role with user form AD in source. This is main problem. I successfuly auth to VPN via SAML, but traffic don't hit my rule.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 11:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264845#M1406</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T11:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264846#M1407</link>
      <description>&lt;P&gt;Do you see anything when you run pdp monitor user and then that username? If not, then thats your issue. However, if you do see results, maybe try disable rule, install policy-re-enable, install again, test.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 11:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264846#M1407</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T11:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264850#M1408</link>
      <description>&lt;P&gt;Below output drom pdp command executed on firewall&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pdp.png" style="width: 633px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32375i75ADF06818831E85/image-dimensions/633x331?v=v2" width="633" height="331" role="button" title="pdp.png" alt="pdp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried your suggestion but without effect. In my opinion user in access role is not mapping to user from VPN authentication. But i don't know why.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 12:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264850#M1408</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264853#M1409</link>
      <description>&lt;P&gt;I think I know why. I saw somewhere name has to start with ext and that is a requirement. let me see if I can find it.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 12:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264853#M1409</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T12:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264854#M1410</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/132620"&gt;@Jakub132620&lt;/a&gt;&amp;nbsp;Sorry my bad, name does not have to start with that, but it seems it should match with what you have on Azure side, so can you give it same name that starts with aad?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 12:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264854#M1410</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T12:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264855#M1411</link>
      <description>&lt;P&gt;Also, make sure to follow these:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 12:41:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264855#M1411</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T12:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264866#M1412</link>
      <description>&lt;P&gt;I read the article you linked to. However, there's one point I don't understand. In the "Configuration in Microsoft Azure Portal" section, we create a custom application for downloading users.&lt;/P&gt;&lt;P&gt;My application was created according to point 1. However, I'm having trouble with point 2.&lt;/P&gt;&lt;P&gt;When I go to the Single Sign-ON tab in my application and select SAML, I can't select specific claims because the first step in the application requires configuring the Basic SAML configuration section. I configured the Basic SAML configuration section in the Checkpoint Remote Secure Access VPN application from the gallery, which is used for VPN authentication via SAML.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 13:16:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264866#M1412</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T13:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264867#M1413</link>
      <description>&lt;P&gt;How can i check this ?&lt;/P&gt;&lt;P&gt;In Entra i can see the same user.principalname as in&amp;nbsp;&lt;SPAN&gt;on-prem AD&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 13:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264867#M1413</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T13:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264868#M1414</link>
      <description>&lt;P&gt;Mind pasting part you are referring to?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 13:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264868#M1414</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T13:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264871#M1415</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jakub132620_0-1765286598817.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32379iD98AEF64B13CFBEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jakub132620_0-1765286598817.gif" alt="Jakub132620_0-1765286598817.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm#" target="_blank" rel="noopener"&gt;Configuring&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;as a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Single Sign-On&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for your Azure application&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Click on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Home&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Azure Active Directory&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;from the menu.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Enterprise applications&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and go to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;All applications&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select your application.&lt;/P&gt;&lt;P&gt;The application&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Overview&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window opens.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Single Sign-On&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;as the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Single Sign-On&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;method.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class=""&gt;Set up Sign-On with&amp;nbsp;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;window, go to the&amp;nbsp;&lt;SPAN class=""&gt;User Attributes &amp;amp; Claims&lt;/SPAN&gt;&amp;nbsp;section and click the pencil icon to edit the claims.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;User Attributes &amp;amp; Claims&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window opens.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Required claim&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Unique User Identifier (Name ID)&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Manage claim&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Attribute&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option - Select.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Source Attribute&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drop-down menu - Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;user.localuserprincipalname&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Save&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to save the user claims, then close the window.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Back on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Signing Certificate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page, go to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Federation Metadata XML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Download&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The Federation Metadata XML is downloaded.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;I can't set the appropriate claim because, as I wrote above, the first step in the application requires configuring the Basic SAML configuration section. I configured the Basic SAML configuration section in the Checkpoint Remote Secure Access VPN application from the gallery, which is used for VPN authentication via SAML.&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Dec 2025 13:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264871#M1415</guid>
      <dc:creator>Jakub132620</dc:creator>
      <dc:date>2025-12-09T13:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264872#M1416</link>
      <description>&lt;P&gt;I see. That link is what we always give to customers if there is an issue, though we help them with the setup. Might be worth opening TAC case then.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 13:26:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264872#M1416</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T13:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264880#M1417</link>
      <description>&lt;P&gt;In&amp;nbsp;&lt;SPAN class=""&gt;SmartConsole&lt;/SPAN&gt;, create an internal User Group object with this name (case-sensitive, spaces not supported):&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;EXT_ID_&amp;lt;&lt;EM&gt;Name_of_Role&lt;/EM&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For example, for a role in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Identity Provider&lt;/SPAN&gt;'s interface with the name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;my_group&lt;/SPAN&gt;, create an internal User Group object in&amp;nbsp;&lt;SPAN class=""&gt;SmartConsole&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with the name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EXT_ID_my_group.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 15:04:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264880#M1417</guid>
      <dc:creator>ishuyell</dc:creator>
      <dc:date>2025-12-09T15:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264881#M1418</link>
      <description>&lt;P&gt;Right, I recall seeing that, but cant find official documentation where it states to do so...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 15:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264881#M1418</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T15:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPM and SAML with Entra ID</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264882#M1419</link>
      <description>&lt;P&gt;Just spoke with a colleague and he said thats how he did it for a customer and it did work, was not in any doc nesessarily.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 15:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-and-SAML-with-Entra-ID/m-p/264882#M1419</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-09T15:36:25Z</dc:date>
    </item>
  </channel>
</rss>

