<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Mobile for Windows - Machine certificate before logon, IdP Azure after logon in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/152055#M6552</link>
    <description>&lt;P&gt;SAML Authentication can (currently) only be triggered after the user is logged in.&lt;BR /&gt;This is likely why Secure Domain Login and SAML authentication aren't supported together, which would be the ideal way to solve this issue.&lt;BR /&gt;I'm guessing when the request for SAML authentication is triggered, the existing VPN connection is killed.&lt;/P&gt;
&lt;P&gt;Given the above, I'm kinda surprised it works the way you describe it.&lt;BR /&gt;Getting it to work in the desired manner is probably an RFE you should raise with the local Check Point office.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jun 2022 19:44:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-06-29T19:44:45Z</dc:date>
    <item>
      <title>Check Point Mobile for Windows - Machine certificate before logon, IdP Azure after logon</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151662#M6549</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Here is what I want to get done :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Machine authentication before logon, (Pre logon)&lt;/LI&gt;&lt;LI&gt;After logon keep this connection alive (Post Logon)&lt;/LI&gt;&lt;LI&gt;Switch to User authentication with IdP Azure MFA.&lt;BR /&gt;And let's hope I can explain Azure to do MFA while "On-Prem"&amp;nbsp; - other outgoing IP to 0365 for RemoteAccess?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So far I have made&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Machine Authentication work via Certificate (ADCS) Pre- and Post-Logon.&lt;/LI&gt;&lt;LI&gt;Get User authentication work with MFA (with Pre-Machine Certficate Auth)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Now, the issue starts :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Either have Pre and Post Machine certificate (but not have MFA)&lt;BR /&gt;Issue is 'post-it' password on the PC = At theft they are on our network!&lt;/LI&gt;&lt;LI&gt;Either have Pre Machine and Post MFA, but with a gap between the post-logon moment and validating MFA.&lt;BR /&gt;Issue, as it's a gap in what we try to achieve, be always behind out protect solution.&amp;nbsp;&lt;BR /&gt;No logon or proper AD auth at logon.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Or am I missing somewhere, a parameter or a trick to make the switch work as described.&lt;/P&gt;&lt;P&gt;It has been a long journey to get to this point, the last mile is seaming to be the biggest hurdle.&lt;/P&gt;&lt;P&gt;Ps, I'm interrested in your POV, but stick to the topic please.&lt;/P&gt;&lt;P&gt;Kind regards&lt;BR /&gt;Tim&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 19:39:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151662#M6549</guid>
      <dc:creator>TimV</dc:creator>
      <dc:date>2022-06-23T19:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile for Windows - Machine certificate before logon, IdP Azure after logon</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151664#M6550</link>
      <description>&lt;P&gt;Want to make sure I understand what you’re trying to achieve here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You want a Remote Access VPN to be connected via Machine Certificate prior to Windows logon&lt;/LI&gt;
&lt;LI&gt;After Windows login, you want to reconfirm &amp;nbsp;with MFA from Azure AD to keep the VPN connection alive (presumably dropping said connection if the user fails MFA)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Am I understanding this correctly?&lt;BR /&gt;Not sure this is actually possible.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 21:10:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151664#M6550</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-23T21:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile for Windows - Machine certificate before logon, IdP Azure after logon</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151676#M6551</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Pre-logon part : absolutely correct.&lt;/P&gt;&lt;P&gt;Post-logon = Machine Certificate that switches over to User MFA.&lt;/P&gt;&lt;P&gt;The key piece is to keep a connection alive between post-logon and confirmation by User MFA.&amp;nbsp;&lt;BR /&gt;This gap causes logon process to not complete succesfully, and only comes back after the User MFA has completed.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 06:12:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/151676#M6551</guid>
      <dc:creator>TimV</dc:creator>
      <dc:date>2022-06-24T06:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile for Windows - Machine certificate before logon, IdP Azure after logon</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/152055#M6552</link>
      <description>&lt;P&gt;SAML Authentication can (currently) only be triggered after the user is logged in.&lt;BR /&gt;This is likely why Secure Domain Login and SAML authentication aren't supported together, which would be the ideal way to solve this issue.&lt;BR /&gt;I'm guessing when the request for SAML authentication is triggered, the existing VPN connection is killed.&lt;/P&gt;
&lt;P&gt;Given the above, I'm kinda surprised it works the way you describe it.&lt;BR /&gt;Getting it to work in the desired manner is probably an RFE you should raise with the local Check Point office.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 19:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-for-Windows-Machine-certificate-before-logon/m-p/152055#M6552</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-29T19:44:45Z</dc:date>
    </item>
  </channel>
</rss>

