<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML Azure AD - Remote access Access Role policy in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202249#M4229</link>
    <description>&lt;P&gt;Can you maybe send some screenshots of the rule in question, as well as groups referenced and the log showing that access? I think that would help us...please blur out any sensitive info.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 20:43:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-01-04T20:43:41Z</dc:date>
    <item>
      <title>SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202237#M4228</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;I have a problem now on implementation when using SAML Azure AD authentication. Everything is working - authentication etc. Users can login properly - connectivity is ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that from the moment I added groups to the cp application in azure, even if there is no rule - the authorized users have access to all the networks. If they are restricted by a certain rule they still have access to all the networks, and the rule not working. Does anyone have an idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to those who answered!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 18:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202237#M4228</guid>
      <dc:creator>Refaeliko</dc:creator>
      <dc:date>2024-01-04T18:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202249#M4229</link>
      <description>&lt;P&gt;Can you maybe send some screenshots of the rule in question, as well as groups referenced and the log showing that access? I think that would help us...please blur out any sensitive info.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 20:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202249#M4229</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-04T20:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202258#M4230</link>
      <description>&lt;P&gt;You've created the necessary groups in SmartConsole, correct?&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You've added those groups to the relevant Access Role objects, correct?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 22:37:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202258#M4230</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-04T22:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202260#M4231</link>
      <description>&lt;P&gt;Of course&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 22:51:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202260#M4231</guid>
      <dc:creator>Refaeliko</dc:creator>
      <dc:date>2024-01-04T22:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202261#M4232</link>
      <description>&lt;P&gt;This is exactly the point that the rule has no effect on the Azure users. Even if there is no rule on the azure users - all networks are open for these users. Even if there is a rule that blocks it, everything is still open. On the other hand, Legacy users work according to the rules. There was one case that stopped the access and it was that I created a rule that blocks 'all users' and then everything was blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the screenshots are still important to you - I will send them.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 23:04:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/202261#M4232</guid>
      <dc:creator>Refaeliko</dc:creator>
      <dc:date>2024-01-04T23:04:57Z</dc:date>
    </item>
  </channel>
</rss>

