<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode. in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129444#M5751</link>
    <description>&lt;P&gt;Keep in mind AD Query does two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Gets events from the AD server over WMI for login events&lt;/LI&gt;
&lt;LI&gt;Queries LDAP for the relevant groups&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Which means it’s not directly processing the MFA at all, nor does it really care where AD sits provided it is accessible.&lt;BR /&gt;Whether this works with Hybrid Connect Mode or not is a different matter.&lt;BR /&gt;I’m assuming the LDAP piece will fail since SMB appliances do not currently support LDAP over SSL, which presumably will be required for any hosted AD.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 21:59:20 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-09-14T21:59:20Z</dc:date>
    <item>
      <title>AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129309#M5724</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I believe that using AD Query is the quickest and easiest (and only way) to natively integrate MS AD MFA authentication and logging (MS AD Hybrid Connect mode) into the the SMB appliances running R80.20.30 on the Embedded Gaia OS?&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301&amp;amp;partition=Basic&amp;amp;product=Identity#You%20can%20configure%20each%20gateway%20to%20connect%20to%20different%20Domain%20Controllers%20in%20the%20same%20account%20unit" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301&amp;amp;partition=Basic&amp;amp;product=Identity#You%20can%20configure%20each%20gateway%20to%20connect%20to%20different%20Domain%20Controllers%20in%20the%20same%20account%20unit&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that correct? Is Secure Platform 2.6 the same OS as Embedded Gaia in this article?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I notice that Radius Accounting and Identity Collector features that come with the full Gaia OS is not supported as per SK159772.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159772#Supported%20Features" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159772#Supported%20Features&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 17:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129309#M5724</guid>
      <dc:creator>Beagle15</dc:creator>
      <dc:date>2021-09-13T17:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129327#M5726</link>
      <description>&lt;P&gt;You are correct, AD Query is the only option on SMB appliances beyond sharing identities from a non-SMB gateway.&lt;BR /&gt;SPLAT is legacy and is not the same as Embedded Gaia.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 19:37:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129327#M5726</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-13T19:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129328#M5727</link>
      <description>&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 19:38:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129328#M5727</guid>
      <dc:creator>Beagle15</dc:creator>
      <dc:date>2021-09-13T19:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129426#M5742</link>
      <description>&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Sorry two more clarifications:&lt;/P&gt;&lt;P&gt;-Can you confirm if the AD Query feature fully supports an Active Directory on-premise in Hybrid Connect Mode and also Azure AD in the cloud only? I don't believe it matters where the AD is located? On-premise or in the cloud?&lt;/P&gt;&lt;P&gt;- Can you confirm if MFA and SSO via MS Azure AD are fully supported by the AD Query feature on the SMB appliances? I can't find any documentation to show what MFA and SSO features the AD Query feature supports? Are these the correct links? ie on the SMB appliances do you get the full features of the Identity Awareness blade or is AD Query just a subset of the full Identity Awareness blade and MFA and SSO is not supported? In my mind as long as you can connect to the AD both MFA and SSO support should be seamless?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/check-point-identity-awareness-tutorial" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/check-point-identity-awareness-tutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Using-Azure-AD-for-Authorization.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Many thanks for any extra insights?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 17:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129426#M5742</guid>
      <dc:creator>Beagle15</dc:creator>
      <dc:date>2021-09-14T17:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129444#M5751</link>
      <description>&lt;P&gt;Keep in mind AD Query does two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Gets events from the AD server over WMI for login events&lt;/LI&gt;
&lt;LI&gt;Queries LDAP for the relevant groups&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Which means it’s not directly processing the MFA at all, nor does it really care where AD sits provided it is accessible.&lt;BR /&gt;Whether this works with Hybrid Connect Mode or not is a different matter.&lt;BR /&gt;I’m assuming the LDAP piece will fail since SMB appliances do not currently support LDAP over SSL, which presumably will be required for any hosted AD.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 21:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129444#M5751</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-14T21:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129445#M5752</link>
      <description>&lt;P&gt;Hello, thank you so can the SMB appliances support MS MFA with Azure AD and the Authenticator App out of the box and if so how is it done? This link below seems to imply yes but what are the pre-requisites? Can you show me an SK or some documentation in the MS Azure AD App Gallery that advises this for the SMB appliances?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.checkpoint.com/2021/05/17/check-point-software-announces-new-microsoft-integrations-at-rsa-conference-2021-to-make-enterprises-more-resilient/" target="_blank"&gt;https://blog.checkpoint.com/2021/05/17/check-point-software-announces-new-microsoft-integrations-at-rsa-conference-2021-to-make-enterprises-more-resilient/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Check Point Remote Access VPN with Azure Active Directory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Check Point VPN is a tried-and-true solution which is now available in the Azure Active Directory (Azure AD) app gallery. Check Point VPN customers can now quickly enable single sign-on and manage access to the Check Point VPN with Azure AD.&lt;/P&gt;&lt;P&gt;By integrating with Azure AD, organizations can leverage capabilities such as Conditional Access and passwordless authentication to provide secure and seamless access to Check Point VPN.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Conditional Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;allows admins to enforce specific requirements (multi-factor authentication, access from a compliance device, have an approved client app, and more) for a user to act on before granting access into the Check Point VPN.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Passwordless authentication&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is a more convenient and secure method of authentication that replaces easily compromised simple passwords. Passwordless authentication methods that integrate with Azure AD include FIDO2 security keys, Windows Hello for Business and Microsoft Authenticator app. Customers can now use passwordless authentication to sign into the Check Point VPN.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;By integrating with Azure AD, Check Point’s VPN solution can support advanced security capabilities that can help organizations on their Zero Trust journey.&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 22:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129445#M5752</guid>
      <dc:creator>Beagle15</dc:creator>
      <dc:date>2021-09-14T22:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129446#M5753</link>
      <description>&lt;P&gt;In that context, the answer is no, this will definitely not work on SMB appliances.&lt;BR /&gt;We only recently added this to our regular appliances running R80.40 and above in the recent JHFs.&amp;nbsp;&lt;BR /&gt;More details here: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/SAML-Support-for-Remote-Access-VPN/m-p/117199" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/SAML-Support-for-Remote-Access-VPN/m-p/117199&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 23:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129446#M5753</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-14T23:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query feature with SMB Appliances to support MS Azure AD MFA in Hybrid Connect mode.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129448#M5754</link>
      <description>&lt;P&gt;Many thanks. If a radius server and NPS was used would it work around this issue on the OS? &lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20.30/AdminGuides/Centrally_Managed/EN/Topics/Managing-Authentication-Servers.htm?Highlight=radius" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R80.20.30/AdminGuides/Centrally_Managed/EN/Topics/Managing-Authentication-Servers.htm?Highlight=radius&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Solution design would be like this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 00:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/AD-Query-feature-with-SMB-Appliances-to-support-MS-Azure-AD-MFA/m-p/129448#M5754</guid>
      <dc:creator>Beagle15</dc:creator>
      <dc:date>2021-09-15T00:39:17Z</dc:date>
    </item>
  </channel>
</rss>

