Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TRajkumar
Contributor
Contributor

User Based policies with Azure AD

Hello Everyone,

 I have a requirement to enforce user based policies in checkpoint firewall with Azure AD. We have integrated the Azure AD with checkpoint firewall (MGMT server in S1C). I able to view the users when creating the access roles but policy enforcement is not happening during the traffic.

At the same time, i don't want captive portal authentication from firewall. since already user did multiple authentication to connect the network. If transparent authentication is possible please suggest.

Does any one have solution kindly help me on this.

Note: I don't have any Domain controller.

Thanks

Rajkumar T

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

For Identity Awareness to work correctly with Azure AD, Captive Portal is required.
See: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide...
Without this, the gateway cannot see the authentication and authorization information, which is otherwise encrypted via TLS.
This will be transparent to users.

0 Kudos
Royi_Priov
Employee
Employee

Hi @TRajkumar 

The proper way to allow SSO with Entra ID is with Check Point Identity and Trust (formerly known as Infinity Identity).

Identity and Trust gets the IP to identity association from both Microsoft Intune and Defender.

Please read more about it here:

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Identity-Admin-Guide...

 

https://www.checkpoint.com/resources/items/solution-brief-check-point-identity-and-trust

If you have additional questions, please let me know.

Thanks,
Royi Priov
R&D Group manager, Identity and Trust (formerly known as Infinity Identity)
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events