<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enforcing SSO for most users but still allowing Username / Password for others using Endpoint VP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163241#M5894</link>
    <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;BR /&gt;I think I am missing something in my knowledge here.&lt;BR /&gt;How does the Username / Password option know who can log in?&lt;/P&gt;&lt;P&gt;Is it all users defined under users / identiies? This would mean everyone defined there can login (assuming correct creds), after which their access is controlled by policy?&lt;BR /&gt;I think this is making sense, and I think my ultimate answer will be to set up external user profiles for my very few current local users and then remove the username/password authentication method, or perhaps I could assign them a certificate and use that option.&lt;/P&gt;</description>
    <pubDate>Sat, 26 Nov 2022 04:08:23 GMT</pubDate>
    <dc:creator>nzmatto1</dc:creator>
    <dc:date>2022-11-26T04:08:23Z</dc:date>
    <item>
      <title>Enforcing SSO for most users but still allowing Username / Password for others using Endpoint VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163116#M5892</link>
      <description>&lt;P&gt;Hi team,&amp;nbsp;&lt;BR /&gt;I have enabled SSO for all our internal VPN users and this is now at a point where I wish to disable the username / password capability, however we have a few external clients who have access to our VPN too. Those external clients use accounts which are configured locally on the firewall.&lt;/P&gt;&lt;P&gt;Is there any way I can permit only people with local accounts access to use the old login feature whilst forcing all other users to use SSO only?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't seem to find any logical way of achieving this and suspect I'm just missing something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 20:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163116#M5892</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2022-11-24T20:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing SSO for most users but still allowing Username / Password for others using Endpoint VP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163222#M5893</link>
      <description>&lt;P&gt;You can’t really force it, unfortunately, as both login options will be presented to everyone.&lt;BR /&gt;Only the users who are locally defined will be able to use the old method, though.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 20:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163222#M5893</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-25T20:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing SSO for most users but still allowing Username / Password for others using Endpoint VP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163241#M5894</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;BR /&gt;I think I am missing something in my knowledge here.&lt;BR /&gt;How does the Username / Password option know who can log in?&lt;/P&gt;&lt;P&gt;Is it all users defined under users / identiies? This would mean everyone defined there can login (assuming correct creds), after which their access is controlled by policy?&lt;BR /&gt;I think this is making sense, and I think my ultimate answer will be to set up external user profiles for my very few current local users and then remove the username/password authentication method, or perhaps I could assign them a certificate and use that option.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 04:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enforcing-SSO-for-most-users-but-still-allowing-Username/m-p/163241#M5894</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2022-11-26T04:08:23Z</dc:date>
    </item>
  </channel>
</rss>

