<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFA VPN screen does not appear on Logon screen in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/242887#M2414</link>
    <description>&lt;P&gt;Dear PhoneBoy&lt;/P&gt;&lt;P&gt;You mean we have to drop authentication with SAML and move to QR code according to this SK?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk102796" target="_blank"&gt;sk102796 - Creating a QR Code using CPQRGen for Mobile applications&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 07:52:43 GMT</pubDate>
    <dc:creator>MarcuzShinz</dc:creator>
    <dc:date>2025-03-04T07:52:43Z</dc:date>
    <item>
      <title>MFA VPN screen does not appear on Logon screen</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/241201#M2412</link>
      <description>&lt;P&gt;Dear Guy!&lt;/P&gt;&lt;P&gt;Currently, we are facing an issue with remote access VPN connectivity on Check Point, specifically:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;We are deploying Check Point VPN with MFA via Azure. When we log in to Windows and initiate the VPN connection, an MFA popup appears for authentication, and the connection is successfully established.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The issue we are encountering is that when we attempt to connect to the VPN from the Windows logon screen, the MFA popup does not appear, causing the VPN connection to fail.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;=&amp;gt; Is there a way to configure the system to display the MFA popup outside the Windows logon screen?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 09:14:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/241201#M2412</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2025-02-14T09:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: MFA VPN screen does not appear on Logon screen</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/241237#M2413</link>
      <description>&lt;P&gt;The ability to prompt for VPN connection before Windows login is a feature we call SDL (Secure Domain Logon).&lt;BR /&gt;Because there is no user at the Windows login screen and a browser is needed to perform the authentication, the browser runs with the only permissions it has: SYSTEM.&lt;BR /&gt;That's potentially dangerous and thus why we do not support SDL with SAML authentication.&lt;/P&gt;
&lt;P&gt;Having said that, we've come up with a different authentication flow for this use case that is more secure.&lt;BR /&gt;Specifically, instead of authenticating on the local browser, a QR code is displayed which you can use to complete the authentication flow from a different device.&lt;BR /&gt;However, it is currently only available as a customer release tied to a specific version/JHF level and VPN client release.&lt;BR /&gt;Contact your local Check Point office for additional information.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 20:03:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/241237#M2413</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-14T20:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: MFA VPN screen does not appear on Logon screen</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/242887#M2414</link>
      <description>&lt;P&gt;Dear PhoneBoy&lt;/P&gt;&lt;P&gt;You mean we have to drop authentication with SAML and move to QR code according to this SK?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk102796" target="_blank"&gt;sk102796 - Creating a QR Code using CPQRGen for Mobile applications&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 07:52:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/242887#M2414</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2025-03-04T07:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: MFA VPN screen does not appear on Logon screen</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/242992#M2415</link>
      <description>&lt;P&gt;The SK you referred to is relevant to creating a QR Code for adding a site to the Check Point Mobile (iOS and Android) app.&lt;BR /&gt;It's not relevant to the issue here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is the SAML authentication must be done on a web browser.&lt;BR /&gt;The browser that runs at the Windows Login (where you perform SDL) runs with SYSTEM permissions, which is dangerous.&lt;BR /&gt;The QR code in question is to allow you complete the SAML authentication process on a different device (e.g. mobile phone).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As stated previously, the functions that perform the above are not present in the product today.&lt;BR /&gt;They are only available in a specific customer release available from your local office.&lt;BR /&gt;I assume this will be added to the product in the future, but don't know the specific timeframe for this.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 20:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-VPN-screen-does-not-appear-on-Logon-screen/m-p/242992#M2415</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-04T20:55:58Z</dc:date>
    </item>
  </channel>
</rss>

