<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML Azure AD - Remote access Access Role policy in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/149707#M7151</link>
    <description>&lt;P&gt;i have the same issue on r81.10 take 45 ,&amp;nbsp;Is there a public SK on this?&lt;/P&gt;</description>
    <pubDate>Mon, 30 May 2022 09:11:38 GMT</pubDate>
    <dc:creator>lrossi89</dc:creator>
    <dc:date>2022-05-30T09:11:38Z</dc:date>
    <item>
      <title>SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/142690#M7148</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having a problem now on implementation when using SAML Azure AD authentication. Everything is working - authentication etc. Users can login properly - connectivity is ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is that when we use the access role and choose a specific user / group - the access role is not working and traffic goes thru Clean up rule. Access role works when it is set to "Any Authenticated" but this would not be helpful when there are multiple user with different access. Any help is appreciated - is there a special config or is this a limitation. We are running R81 + JHF 56 (latest)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/142690#M7148</guid>
      <dc:creator>support_suppor1</dc:creator>
      <dc:date>2022-03-01T13:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/142945#M7149</link>
      <description>&lt;P&gt;Are you sure the application in Azure AD is set up per here?&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm?Highlight=graph" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm?Highlight=graph&lt;/A&gt;&lt;BR /&gt;The groups needed for Azure AD are retrieved via the Graph API (supported in R81 and above).&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 23:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/142945#M7149</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-03T23:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/145256#M7150</link>
      <description>&lt;P&gt;Had the same&amp;nbsp; issue on R81, login to Azure SAML worked fine&amp;nbsp; but after that&amp;nbsp; ,&amp;nbsp; &amp;nbsp;cleanup rule was used&amp;nbsp; instead&amp;nbsp; of the specific access role policy rule.&amp;nbsp; TAC&amp;nbsp; provided a hotfix and this started working after we applied the hotfix to the gateway and installed the policy.&amp;nbsp; Hotfix will be custom and dependent on your HFA level.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 14:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/145256#M7150</guid>
      <dc:creator>Zoran_Filipac</dc:creator>
      <dc:date>2022-04-01T14:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/149707#M7151</link>
      <description>&lt;P&gt;i have the same issue on r81.10 take 45 ,&amp;nbsp;Is there a public SK on this?&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 09:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/149707#M7151</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2022-05-30T09:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/149735#M7152</link>
      <description>&lt;P&gt;can you share the&amp;nbsp;SR# number ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 14:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/149735#M7152</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2022-05-30T14:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161847#M7153</link>
      <description>&lt;P&gt;We had same issue. After SAML authentication (Azure AD), Users were not able to access LAN networks. Access role was not matched. We followed below steps to resolve issue.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 398px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18369iF3E73852E07B17E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I have different problem. I cannot use mobile access application with Azure IDP access role as per sk171557. I am checking if I need to use simple "destination" field to restrict user for specific destination or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 09:44:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161847#M7153</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2022-11-11T09:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161850#M7154</link>
      <description>&lt;P&gt;Check this :&amp;nbsp;&lt;STRONG&gt;sk179788&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179788&amp;amp;partition=Advanced&amp;amp;product=Remote" target="_blank" rel="noopener"&gt;Access Roles are not enforced when using SAML authentication&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 10:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161850#M7154</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2022-11-11T10:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161971#M7155</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Access role issue is already resolved but my concern is how I can use Access role Azure identity with mobile access application to restrict user for certain destination.&lt;/P&gt;
&lt;P&gt;As per sk171557, we cannot do that&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 08:02:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/161971#M7155</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2022-11-14T08:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/167242#M7156</link>
      <description>&lt;P&gt;Through this SK179788 it works, but we are finding an anomaly:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- We are using Azure AD groups directly, and it seems to work correctly.&lt;/P&gt;&lt;P&gt;step -&amp;gt; Using Azure AD for Authorization &lt;A href="https://sc1.checkpoint.com/documents/r81/webadminguides/en/cp_r81_centityAWareness_adminguide/topics-idag/using-azure-for-uthorization.htm?highlight=graph" target="_blank"&gt;https://sc1.checkpoint.com/documents/r81/webadminguides/en/cp_r81_centityAWareness_adminguide/topics-idag/using-azure-for-uthorization.htm?highlight=graph&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;- But in a random way sometimes the firewall "not retrieve the correct group from AD Azure" and makes the retrieval from the LOCAL LDAP groups (from local Active Directory), and in this case VPN connections doesn't work because non match the correct AR Azure.&lt;/P&gt;&lt;P&gt;Then just after an install policy everything recovers and the firewall retrieve the correct information from azure&lt;/P&gt;&lt;P&gt;Has anyone made this integration, without setting manual groups and works without anomalies?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 10:05:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/167242#M7156</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2023-01-10T10:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/167266#M7157</link>
      <description>&lt;P&gt;Sounds like a bug and I recommend opening a TAC case.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 13:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/167266#M7157</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-10T13:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Azure AD - Remote access Access Role policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/180778#M7158</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Step 1 - d&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Click &lt;SPAN class="Menu_Options"&gt;New Application &amp;gt; Non-gallery application&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Can we use the pre populated Checkpoint Secure VPN access application or is the specific requirement to create a new non-gallery application? what is the reason.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 01:10:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Azure-AD-Remote-access-Access-Role-policy/m-p/180778#M7158</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-05-13T01:10:57Z</dc:date>
    </item>
  </channel>
</rss>

