<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capsule Workspace Oauth in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170557#M5650</link>
    <description>&lt;P&gt;This may be necessary for the GW to find the tenant, the authentication itself uses the primary smtp address.&lt;/P&gt;&lt;P&gt;You can see this address in the top of your screen in the settings on the capsult client.&lt;/P&gt;&lt;P&gt;Is all working in your environment now ?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 10:14:48 GMT</pubDate>
    <dc:creator>Lars_de_Mooy</dc:creator>
    <dc:date>2023-02-07T10:14:48Z</dc:date>
    <item>
      <title>Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168633#M5630</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We used Capsule Workspace for business mail for many years, the best advantage is that you only have to allow a connection from the public IP to exchange online and you can block all the rest. Capsule is making a connection to the remote access gateway and the remote access gateway makes a session to ExO.&lt;/P&gt;&lt;P&gt;Now last week Microsoft finaly depricated basic auth in ExO that Capsule needs to connect.&lt;/P&gt;&lt;P&gt;The only way to make the connection again is to upgrade to R81.20 that had the Oauth for Capsule Workspace option.&lt;/P&gt;&lt;P&gt;We upgraded our environment and configured the enterprise app in Azure and made all the configs on the mobile asscess GW on the checkpioint side. The problem is that the authentication to the Mobile access GW is all fine but the authentication to Azure Oauth ends up with a 401 error. I spended last week to troubleshoot and created all the relevant logging.&lt;/P&gt;&lt;P&gt;Is there anyone that have this setup working that may faced the same issues and was able to fix them ?&lt;/P&gt;&lt;P&gt;I am at the end of my knowlage and need this to work asap.&lt;/P&gt;&lt;P&gt;Hope someone has some good tips to get us in the right track.&lt;/P&gt;&lt;P&gt;Best rgrds Lrs&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 15:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168633#M5630</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-01-21T15:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168634#M5631</link>
      <description>&lt;P&gt;I presume you’ve opened a TAC case in parallel?&lt;BR /&gt;In any case, sharing whatever debug you’ve collected might be helpful.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 15:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168634#M5631</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-21T15:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168663#M5632</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Yes i have a TAC case&lt;/P&gt;&lt;P&gt;Right after i login i get a new prompt "Enter your Mail credentials" if i fill in this credentials i see this logging&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99053&amp;amp;partition=Basic&amp;amp;product=Mobile" target="_blank" rel="noopener"&gt;How to debug Mobile Access Web Applications (checkpoint.com)&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;tail -f $CVPNDIR/log/httpd.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;[4606][22 Jan 10:58:28][SERIALIZE] [CVPN_INFO] getDecoder: Using fwobj-based RPC decoder&lt;BR /&gt;[4606][22 Jan 10:58:28][SERIALIZATION] [CVPN_INFO] CvpnIS::FwobjDeserializer::createObject: deserializing object of class: PortalCustomizationResponse&lt;BR /&gt;[4606][22 Jan 10:58:28][SERIALIZATION] IDeserializable::createObject: found CreateFunc (0xf1c5c110) for className: PortalCustomizationResponse&lt;BR /&gt;[4606][22 Jan 10:58:28][APACHE] [CVPN_INFO] Mod_input_filter: Handling HTTP (not SOCKS) traffic&lt;BR /&gt;[Sun Jan 22 10:58:28.454160 2023] [wi:debug] [pid 4606] WIConnection.cpp(220): parsing: (body printout skipped)&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::getRequestNumber: WIConnection::getRequestNumber m_requestNumber=1&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::isCriticalError: WIConnection::IsCriticalError isCriticalError=false&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIInputFilter::shouldHandleInFilter: handleInFilter = true&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIInputFilter::checkParseResult: handleInFilter&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::getRequestNumber: WIConnection::getRequestNumber m_requestNumber=1&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::isCriticalError: WIConnection::IsCriticalError isCriticalError=false&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIInputFilter::checkParseResult: no errors or no relevant errors&lt;BR /&gt;[Sun Jan 22 10:58:28.455897 2023] [deflate:debug] [pid 4606] mod_deflate.c(873): [client x.x.x.x:52824] AH01384: Zlib: Compressed 171 to 156 : URL /Errors/ErrorDocument, referer: &lt;A href="https://capsule.cocensus.nl/sslvpn/MobileApp/" target="_blank" rel="noopener"&gt;https://capsule.xxxxxxx/sslvpn/MobileApp/&lt;/A&gt;&lt;BR /&gt;[4606][22 Jan 10:58:28][APACHE] [CVPN_INFO] Mod_input_filter: Handling HTTP (not SOCKS) traffic&lt;BR /&gt;[4606][22 Jan 10:58:28][APACHE] [CVPN_INFO] Cvpn::ApacheRequest::~ApacheRequest: (/Errors/ErrorDocument)&lt;BR /&gt;[4606][22 Jan 10:58:28][BusinessMail] [CVPN_INFO] Cvpn::BusinessMailHandler::~BusinessMailHandler: Dtor&lt;BR /&gt;[4606][22 Jan 10:58:28][CURL_BASED] [CVPN_INFO] Cvpn::CurlBasedHandler::~CurlBasedHandler: Dtor&lt;BR /&gt;[Sun Jan 22 10:58:28.456891 2023] [:debug] [pid 4606] trace_logger_filters.c(321): [client x.x.x.x:52824] in clean request , referer: &lt;A href="https://capsule.cocensus.nl/sslvpn/MobileApp/" target="_blank" rel="noopener"&gt;https://capsule.xxxxxxx/sslvpn/MobileApp/&lt;/A&gt;&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WICreateRequestHook::doExecute: WICreateRequestHook::execute setting current request and body flag&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::setIsBody: WIConnection::setIsBody m_isBody=false&lt;BR /&gt;[4606][22 Jan 10:58:28][WEBINT] [CVPN_INFO] Cvpn::WIConnection::incrementRequestNumber: WIConnection::incrementRequestNumber incremented m_requestNumber=2&lt;BR /&gt;[Sun Jan 22 10:58:28.457456 2023] [:debug] [pid 4606] trace_logger_filters.c(207): [client x.x.x.x:52824] creating request_buffer_handle&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;[4606][22 Jan 10:58:28][APACHE] [CVPN_INFO] Mod_input_filter: Handling HTTP (not SOCKS) traffic&lt;BR /&gt;[4606][22 Jan 10:58:30][WEBINT] [CVPN_INFO] Cvpn::WIInputFilter::parseLoop: ap_get_brigade failed - return false&lt;BR /&gt;[Sun Jan 22 10:58:30.459714 2023] [:debug] [pid 4606] trace_logger_filters.c(244): [client x.x.x.x:52824] get brigade failed&lt;BR /&gt;[Sun Jan 22 10:58:30.459724 2023] [:debug] [pid 4606] trace_logger_filters.c(321): [client x.x.x.x:52824] in clean request&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 10:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/168663#M5632</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-01-22T10:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169325#M5634</link>
      <description>&lt;P&gt;That appears to be the logs from the front end web server.&lt;BR /&gt;I suspect you’ll need to look at a different log file which will contain the actual backend authentication that is occurring with O365.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 19:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169325#M5634</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-26T19:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169505#M5635</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Has Checkpoint released a new guide on how to onboard capsule workspace as an Azure enterprise app ?&lt;/P&gt;&lt;P&gt;Capsule tries to authenticate using basic auth and given its deprecated status, users can no longer log in.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 08:43:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169505#M5635</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-01-29T08:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169509#M5636</link>
      <description>&lt;P&gt;Hi spectumtech&lt;/P&gt;&lt;P&gt;This is the guide that you need please share your findings and report back.&lt;/P&gt;&lt;P&gt;If its not working use EWSEDITOR from github to test the azure part.&lt;/P&gt;&lt;P&gt;On my config the EWSeditor is connecting fine on the azure app, the gateways are not.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Exchange-Mail-Applications-for-Smartphones-and-Tablets.htm?Highlight=oauth" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Exchange-Mail-Applications-for-Smartphones-and-Tablets.htm?Highlight=oauth&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 09:08:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169509#M5636</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-01-29T09:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169510#M5637</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Spend hours and days and hours fixing this the azure app is fine i can connect with EWSeditor using the exact same input as i have on the gateways. I have sent all related logs to checkpoint and i keep waiting on a solution.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 09:10:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169510#M5637</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-01-29T09:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169932#M5638</link>
      <description>&lt;P&gt;Hi spectumtech did you manage to get this working i just spend 2 hours with TAC and no solution yet...&lt;/P&gt;&lt;P&gt;I hope you to hear back and hear how your capsult oauth is doing ?&lt;/P&gt;&lt;P&gt;Regards Lars&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:27:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169932#M5638</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-01T14:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169964#M5639</link>
      <description>&lt;P&gt;I can see that you have an active case with TAC and they are working with you to get the necessary information to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 17:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169964#M5639</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-01T17:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169966#M5640</link>
      <description>&lt;P&gt;Yes thats what ik wrote before and TAC is doing all they can to help me solve this, like they always do.&lt;/P&gt;&lt;P&gt;After working on this for a while i am very curious to know if someone else was able to connect Capsule with Oauth.&lt;/P&gt;&lt;P&gt;Tnxs for the reply and keep you posted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169966#M5640</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-01T18:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169991#M5641</link>
      <description>&lt;P&gt;PhoneBoy&lt;/P&gt;&lt;P&gt;indeed, we have an open case with TAC&lt;/P&gt;&lt;P&gt;No real help at this stage and very slack in responding .&lt;/P&gt;&lt;P&gt;It is most likely due to the deprecation of basic auth in m365. We are able to successfully connect and authenticate to the mobile portal and SNX which used the local AD but when capsule is trying to authenticate to Azure AD (ie m365 - exchange online) authentication fails&amp;nbsp;&lt;/P&gt;&lt;P&gt;we simply need a solid (and working) guide on how to correctly configure the enterprise app in Azure to get capsule workspace to authenticate correctly using modern auth.&lt;/P&gt;&lt;P&gt;not sure why this is taking so long. I am safe to assume that there are quite a few frustrated capsule users out there that can’t use this po until it is resolved ..&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 21:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/169991#M5641</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-01T21:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170011#M5642</link>
      <description>&lt;P&gt;The following confirms the above:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/exchange/client-developer/exchange-web-services/authentication-and-ews-in-exchange" target="_blank"&gt;https://learn.microsoft.com/en-us/exchange/client-developer/exchange-web-services/authentication-and-ews-in-exchange&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is NO guide (tested and validated !) from Checkpoint on how to configure capsule workspace to authenticate as an Azure enterprise app using OAth2.0. Checkpoint&amp;nbsp; - why not ???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 01:34:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170011#M5642</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-02T01:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170029#M5643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Spectrumtech_MS,&lt;/P&gt;&lt;P&gt;Microsoft deprecated basic auth after a long time of communicating and warning and end 2022 and switched off basic in the tenants one at the time.&lt;/P&gt;&lt;P&gt;This is the moment we started to get the 401 unauthenticated error on EWS in smartvier tracker.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Capsule workspace stopped working because of this.&lt;BR /&gt;There was a possibility to turn back on basic on EWS in office 365 to give you some more time and after we did that it started to work again. So it was not a surprise for us that this was about to happen beginning 2023 and we needed a solution for this.&lt;/P&gt;&lt;P&gt;We created a checkpoint case and the only way to get the possibility to use Oauth on mobile access connecting to ews was to upgrade to R81.20 we did. The mobile access guide i posted here gives you the basics on what you need to configure in Azure to make this work. Dont take me wrong but the configuration of the enterprise app in azure ad is no complex configuration and the R81.20 mobile access admin guide i posted here gives all the relevant information to create it and it can be tested easaly with the EWSeditor tool from github.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The fact that the R81.20 release, in which the possibility to use oauth with caspule, was released &lt;STRONG&gt;after&lt;/STRONG&gt; Microsoft switched off&amp;nbsp; basic auth is strange.&amp;nbsp; Checkpoint is investigating my config and i believe this will be solved soon.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 09:09:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170029#M5643</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-03T09:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170370#M5644</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;We have upgraded to R81.20 and the issue persists.&lt;/P&gt;&lt;P&gt;Capsule workspace is NOT using modern auth but rather reverts to basic which, in turn, is rejected by m365.&lt;/P&gt;&lt;P&gt;Regarding the configuration of Azure Enterprise App - Are you able to post the detailed configuration steps to allow the use of OATH2.0 for capsule workspace authentication to Exchange Online as the guide is somewhat vague.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2023 10:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170370#M5644</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-05T10:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170371#M5645</link>
      <description>&lt;P&gt;see attached log extract from the gateway&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2023 10:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170371#M5645</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-05T10:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170372#M5646</link>
      <description>&lt;P&gt;hi please read carefully&lt;/P&gt;&lt;P&gt;-login azure AD&lt;BR /&gt;-click azure active directory&lt;BR /&gt;-click app registrations (not enterprise applications)&lt;BR /&gt;-click new registration leave all default and give name&lt;BR /&gt;-click Client credentials Add a certificate or secret&lt;BR /&gt;-new client secret + give name&lt;BR /&gt;-copy value to txt&lt;BR /&gt;-click api permissions chose APIs my organization uses search offcie 365 exchange online&lt;BR /&gt;-click delegated poermissions seacrh ews open ews chose EWS.AccessAsUser.All click ok&lt;BR /&gt;-chose Office 365 Exchange Online (1) again click application permissions chose full_access_as_app&lt;/P&gt;&lt;P&gt;dont forget to add the redirect url for iOS / Android)&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2023 13:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170372#M5646</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-05T13:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170388#M5647</link>
      <description>&lt;P&gt;Thank you Lars.&lt;/P&gt;&lt;P&gt;All configured but unfortunately Capsule still fails to authenticate with a 401 error in the log&lt;/P&gt;&lt;P&gt;We have an open, escalated ticket with Checkpoint ( which failed to provide any meaningful input to date) so will continue to follow up and update if/when a resolution is found&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 01:06:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170388#M5647</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-06T01:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170548#M5648</link>
      <description>&lt;P&gt;Hi please try this;&lt;/P&gt;&lt;P&gt;- Open your Mobile Mail application in smart dashboard&lt;/P&gt;&lt;P&gt;-go to exchange access&lt;/P&gt;&lt;P&gt;-tick use specific domain&lt;/P&gt;&lt;P&gt;-fill in yourdomain.onmicrosoft.com and save -&amp;gt; policy install&lt;/P&gt;&lt;P&gt;In the basic auth configuration this field had you public domain name that is after the @&lt;/P&gt;&lt;P&gt;In Oauth this needs to be your onmicrosoft domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19484i5C630E781961F09F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 08:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170548#M5648</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-07T08:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170556#M5649</link>
      <description>&lt;P&gt;Thanks Lars.&lt;/P&gt;&lt;P&gt;I think that did the trick&amp;nbsp; (changing the domain to the *.microsoftonline.com)&lt;/P&gt;&lt;P&gt;Is this a prerequisite for OATH2 authentication to AAD/M365 ?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 10:06:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170556#M5649</guid>
      <dc:creator>Spectrumtech_MS</dc:creator>
      <dc:date>2023-02-07T10:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Workspace Oauth</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170557#M5650</link>
      <description>&lt;P&gt;This may be necessary for the GW to find the tenant, the authentication itself uses the primary smtp address.&lt;/P&gt;&lt;P&gt;You can see this address in the top of your screen in the settings on the capsult client.&lt;/P&gt;&lt;P&gt;Is all working in your environment now ?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 10:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Workspace-Oauth/m-p/170557#M5650</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2023-02-07T10:14:48Z</dc:date>
    </item>
  </channel>
</rss>

