<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capsule VPN w/ certificate authentication and authorization from AAD in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202959#M4199</link>
    <description>&lt;P&gt;You claim you're not using SAML, yet you provide links to a SAML-related configuration.&lt;BR /&gt;The only other place to gather groups from is LDAP...is this what you're doing?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 20:47:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-01-12T20:47:49Z</dc:date>
    <item>
      <title>Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202910#M4196</link>
      <description>&lt;P&gt;Hi CheckMates!&lt;BR /&gt;&lt;BR /&gt;I'm working on a PoC for our customer and this is what I'm trying to achieve:&lt;BR /&gt;&lt;BR /&gt;Intune deployment of Capsule VPN for Android using personal certificate for authentication and Azure AD (Entra ID) for authorization. Azure certificate connector takes care of requesting certificate and Intune deploys it to Android device.&amp;nbsp;I followed&amp;nbsp;&lt;A title="Capsule VPN setup in Intune MDM" href="https://support.checkpoint.com/results/sk/sk170320" target="_blank" rel="noopener"&gt;sk170320&lt;/A&gt;. The VPN client deployment with site info, authentication method and pushing the actual certificate is currently working. Also the certificate authentication itself is working by using generic* profile with 'Public Key' option selected as authentication scheme.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;What I need to get working is authorization with Azure AD&lt;/STRONG&gt;. I don't know how to get the user to match a group in AAD (pdp monitor does not show a role for the Android device). I also have a TAC case open where I have explained the case and asked if this is even possible. I haven't gotten a no-no response, so I assume it is possible. I have created Azure AD object and I call pull the groups from the AAD.&lt;BR /&gt;&lt;BR /&gt;I have also tried to follow many different documents about getting the roles from the AAD but all of those refer to SAML. We are not using SAML in this case. Followed&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/SAML-Support-for-Remote-Access-VPN/td-p/117199/page/4" target="_blank" rel="noopener"&gt;this&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A title="Azure AD Auth supplementary instructions.pdf" href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/appliances-and-gaia/23059/1/Azure%20AD%20Auth%20-%20supplementary%20instructions.pdf" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Background why not using SAML.&lt;BR /&gt;&lt;BR /&gt;Devices used here are Android phones. These phones are not personal i.e. they are shared devices and they have multiple users.&lt;BR /&gt;&lt;BR /&gt;One device is for on-call plumber no.1 and when his/her shift ends phone is passed to plumber no. 2. Second device is for nursery and different people there use the common phone for accessing company resources via VPN.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Group info (role) is needed in order to create access roles for the different lines of work because they access different company resources. E.g. group_plumber_android for plumbers and group_nursery_android from nurseries.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Versions:&lt;BR /&gt;Capsule VPN for Android 1.601.25&lt;BR /&gt;Gateway in which the client is terminated to, R81.10 JHF take 129&lt;BR /&gt;Android OS 13&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would really appreciate if someone could help me with this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 10:35:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202910#M4196</guid>
      <dc:creator>rooKing</dc:creator>
      <dc:date>2024-01-12T10:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202911#M4197</link>
      <description>&lt;P&gt;I would suggest to involve CP TAC in a SR# - POC or not should not be an issue...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 11:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202911#M4197</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-01-12T11:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202919#M4198</link>
      <description>&lt;P&gt;Thanks for a swift reply.&lt;BR /&gt;&lt;BR /&gt;As mentioned I have a TAC case open - and it has been open for almost 2 months now. In that SR case we first tried to resolve certificate authentication problem and after that remote access user group problem - thanks to some tidbits of information given to me in this SR I managed eventually tackle those problems myself. Now I have asked TAC to walk me through how to configure the authorization part towards AAD.&lt;BR /&gt;&lt;BR /&gt;I created this post to CheckMates in parallel. I was hoping that someone has been fighting the same problem and might get a solution faster.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 12:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202919#M4198</guid>
      <dc:creator>rooKing</dc:creator>
      <dc:date>2024-01-12T12:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202959#M4199</link>
      <description>&lt;P&gt;You claim you're not using SAML, yet you provide links to a SAML-related configuration.&lt;BR /&gt;The only other place to gather groups from is LDAP...is this what you're doing?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 20:47:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/202959#M4199</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-12T20:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/203097#M4200</link>
      <description>&lt;P&gt;Yes, documents are related to SAML. I was trying to be creative and pickup stuff from those that would be relevant for fetching groups from AAD.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Nevertheless I finally got an answer from TAC last Friday and what I'm trying to do is not possible. So I need to get back to drawing board. Many many hours down the drain.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you for everyone for showing interest on this case.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 13:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/203097#M4200</guid>
      <dc:creator>rooKing</dc:creator>
      <dc:date>2024-01-15T13:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule VPN w/ certificate authentication and authorization from AAD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/203207#M4201</link>
      <description>&lt;P&gt;One more try. Could someone lead me to a new path how to achieve the goal?&lt;BR /&gt;&lt;BR /&gt;And the goal is:&lt;BR /&gt;&lt;BR /&gt;- Deploy Capsule VPN to Android devices via Intune. (This I know now how to do.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;)&lt;BR /&gt;- Authenticate the Android device itself because they are used by group of people instead of just a dedicated user.&lt;BR /&gt;- Group the devices so that the groups can be used for authorization so that a specific group can be used to give access to specific applications&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 11:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-VPN-w-certificate-authentication-and-authorization-from/m-p/203207#M4201</guid>
      <dc:creator>rooKing</dc:creator>
      <dc:date>2024-01-16T11:55:31Z</dc:date>
    </item>
  </channel>
</rss>

