<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure AD - Device Group in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183892#M4802</link>
    <description>&lt;P&gt;If I connect Azure AD as an identity provider, can I then also authorize by device group on azure in addition to by user group? my goal would be to enable a user group only from a particular device group.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 14:10:59 GMT</pubDate>
    <dc:creator>michele</dc:creator>
    <dc:date>2023-06-13T14:10:59Z</dc:date>
    <item>
      <title>Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183892#M4802</link>
      <description>&lt;P&gt;If I connect Azure AD as an identity provider, can I then also authorize by device group on azure in addition to by user group? my goal would be to enable a user group only from a particular device group.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:10:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183892#M4802</guid>
      <dc:creator>michele</dc:creator>
      <dc:date>2023-06-13T14:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183919#M4803</link>
      <description>&lt;P&gt;As long as the group comes across in the SAML Assertion and there is a local group created for it (of the form EXT_ID_xx where xx is the case sensitive name of the group), I don't see why it wouldn't work.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 18:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183919#M4803</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-13T18:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183932#M4804</link>
      <description>&lt;P&gt;Thank you.&lt;BR /&gt;Right now windows clients, I connect in VPN via capsule component (configured on windows built-in vpn); since it only requires user password to connect, I wanted to understand if I could add in addition to a user group, a managed device group; right now the user groups are read via LDAP (AD onprem), however, I would like to understand if I can connect the user/device groups directly on Azure and not change the current connection method (Capusle with user/password) as I would not want to go and install the dedicated checkpoint software to connect in vpn&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 06:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183932#M4804</guid>
      <dc:creator>michele</dc:creator>
      <dc:date>2023-06-14T06:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183991#M4805</link>
      <description>&lt;P&gt;Not currently possible as the authentication method has to be SAML to obtain the user's groups from Azure AD.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 16:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/183991#M4805</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-14T16:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/184524#M4806</link>
      <description>&lt;P&gt;Is there anything I can do so that I can always use capsules though increasing security?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 11:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/184524#M4806</guid>
      <dc:creator>michele</dc:creator>
      <dc:date>2023-06-22T11:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AD - Device Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/184571#M4807</link>
      <description>&lt;P&gt;This isn't supported with the Capsule VPN clients.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 17:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-AD-Device-Group/m-p/184571#M4807</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-22T17:12:10Z</dc:date>
    </item>
  </channel>
</rss>

