<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint VPN MFA in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251995#M1823</link>
    <description>&lt;P&gt;As far as I know the situation with this has not changed.&lt;BR /&gt;Recommend engaging your local Check Point office on this requirement.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jun 2025 20:58:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-06-25T20:58:53Z</dc:date>
    <item>
      <title>Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251761#M1815</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Checkpoint VPN 2 factor authentication has been setup successfully, but now there is a requirement where the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;MFA (multi factor&amp;nbsp;authentication) needs to be enforced on certain users and NOT all users&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ex : - If there are 10 users, 8 of them will be enforced with MFA and the other 2 will not be enforced with MFA.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this possible?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 10:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251761#M1815</guid>
      <dc:creator>bcmario</dc:creator>
      <dc:date>2025-06-23T10:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251762#M1816</link>
      <description>&lt;P&gt;From what Im aware of, its not possible. I asked this exact question while via TAC case and they responded saying escalation team told them it was not feasible. This was back in 2023, but I have not heard otherwise since.&lt;/P&gt;
&lt;P&gt;The only way I can see this working would be if you create local users in smart console and assign them specific auth method.&lt;/P&gt;
&lt;P&gt;Maybe someone else can confirm.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 10:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251762#M1816</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-23T10:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251929#M1817</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;any idea whether this is still not possible or is there a workaround this now?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 03:30:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251929#M1817</guid>
      <dc:creator>bcmario</dc:creator>
      <dc:date>2025-06-25T03:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251934#M1818</link>
      <description>&lt;P&gt;Not sure if this classifies as a workaround but we managed to accomplish this. The catch is we're doing it through MS Authenticator via Entra Conditional Access Policies.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 05:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251934#M1818</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-06-25T05:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251935#M1819</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I believe this depends on how you setup the MFA as what I understand as well, make sure to untick legacy authentication method. Let me know if it works&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 05:57:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251935#M1819</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2025-06-25T05:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251950#M1820</link>
      <description>&lt;P&gt;How did you set up auth methods in smart console gateway object?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 10:13:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251950#M1820</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-25T10:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251956#M1821</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It depends on how you configure IDP. For example, Microsoft azure AD is your IDP then you can enforce 2FA setting in Azure AD. Firewall just forward request to azure AD and it will decide whether to enforce 2FA or not.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 11:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251956#M1821</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2025-06-25T11:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251958#M1822</link>
      <description>&lt;P&gt;Right, but thats generally how it works, not to exclude few users though.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 11:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251958#M1822</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-25T11:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN MFA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251995#M1823</link>
      <description>&lt;P&gt;As far as I know the situation with this has not changed.&lt;BR /&gt;Recommend engaging your local Check Point office on this requirement.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 20:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-VPN-MFA/m-p/251995#M1823</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-25T20:58:53Z</dc:date>
    </item>
  </channel>
</rss>

