<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security VPN on Azure AD Joined PC in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169241#M5584</link>
    <description>&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as phoneboy said, you will need to setup SAML Authentication against Azure IDP for being able to do something there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;check out those videos - that helped me a lot in configuring something like that:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=172xGxqQvhI" target="_blank"&gt;https://www.youtube.com/watch?v=172xGxqQvhI&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.youtube.com/watch?v=yZVB3sJ3fZ8" target="_blank"&gt;https://www.youtube.com/watch?v=yZVB3sJ3fZ8&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Basically your client check is than done by Azure within a conditional access ruleset. Gateway only receives a "OK" or "not OK" including some attributes (i.e. group memberships, maybe Machine attributes are possible too)&lt;/P&gt;&lt;P&gt;So there is nothing like an on prem AD on your site, where machine accounts are replicated to - so one could then go via ldap account unit...?&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2023 08:06:24 GMT</pubDate>
    <dc:creator>Nüüül</dc:creator>
    <dc:date>2023-01-26T08:06:24Z</dc:date>
    <item>
      <title>Endpoint Security VPN on Azure AD Joined PC</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169146#M5581</link>
      <description>&lt;P&gt;Good evening everyone, for the past few weeks I've been going crazy trying to get the VPN working on a PC deployed via Intune (so it's an Azure AD Joined PC), but the machine is in no way recognised by the firewall and therefore does not match any policy.&lt;/P&gt;&lt;P&gt;I believe that this malfunction is related to the fact that we use authentication via a certificate, but this is not loaded on the machine in Azure AD. Am I on the right way or is there something else to check?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:52:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169146#M5581</guid>
      <dc:creator>DanielVd</dc:creator>
      <dc:date>2023-01-25T15:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN on Azure AD Joined PC</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169203#M5582</link>
      <description>&lt;P&gt;If you're using Azure AD, the entire authentication must occur with Azure AD (i.e. via SAML) in order to get the group information.&lt;BR /&gt;This applies regardless of the authentication method you specify in Azure AD.&lt;BR /&gt;That also implies your certificates need to come from Azure AD.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 02:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169203#M5582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-26T02:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN on Azure AD Joined PC</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169238#M5583</link>
      <description>&lt;P&gt;Thanks PhoneBoy. Can you link me to any guides explaining how to configure the remote access section? I have found several, but I cannot get the desired result.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 07:48:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169238#M5583</guid>
      <dc:creator>DanielVd</dc:creator>
      <dc:date>2023-01-26T07:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN on Azure AD Joined PC</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169241#M5584</link>
      <description>&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as phoneboy said, you will need to setup SAML Authentication against Azure IDP for being able to do something there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;check out those videos - that helped me a lot in configuring something like that:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=172xGxqQvhI" target="_blank"&gt;https://www.youtube.com/watch?v=172xGxqQvhI&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.youtube.com/watch?v=yZVB3sJ3fZ8" target="_blank"&gt;https://www.youtube.com/watch?v=yZVB3sJ3fZ8&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Basically your client check is than done by Azure within a conditional access ruleset. Gateway only receives a "OK" or "not OK" including some attributes (i.e. group memberships, maybe Machine attributes are possible too)&lt;/P&gt;&lt;P&gt;So there is nothing like an on prem AD on your site, where machine accounts are replicated to - so one could then go via ldap account unit...?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 08:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169241#M5584</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-01-26T08:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN on Azure AD Joined PC</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169297#M5585</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&amp;amp;partition=Advanced&amp;amp;product=Endpoint&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 15:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-on-Azure-AD-Joined-PC/m-p/169297#M5585</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-26T15:26:52Z</dc:date>
    </item>
  </channel>
</rss>

