Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Royi_Priov
Employee
Employee

How to: Share identities from SASE, Workforce AI, Browse, Endpoint with your Gateways

Hi CheckMates,

Do you run Check Point Security Gateways alongside another Check Point product, such as SASE, Workforce AI, Browse Security, or Endpoint Security? Then there's a capability worth turning on: Identity Sharing.

Screenshot at Oct 07 13-59-00.png

What it does

When one of these products identifies a user or a device, it shares that identity with the Identity and Trust service. Identity and Trust acts as a Policy Decision Point (PDP) as-a-service for Identity Awareness, so your Security Gateways receive this identity information and use it for enforcement.

Why turn it on

1. Sign in once, get recognized everywhere

Your users log in to their endpoint, and the installed Check Point clients recognize them. From that point, your gateways already know who they are and which device they use. You get no extra prompts, no captive portal, and no duplicate identity setup.

Take the SASE Private Access scenario. A user in a branch office connects through the Check Point SASE backbone to a data center. The data center is protected by a firewall with a VPN connection to the data center firewall. The Identity and Trust service learns the login event from SASE, the Entra ID group membership using SCIM or API, and creates the Identity Session. The Identity Session is then shared with the Firewall, and security enforcement is achieved based on the user identities.

2. Bring device posture into your access policy

Endpoint Security knows the health of every device it protects. With Identity Sharing, that posture information reaches your gateways. You can then use it in your policy with our Trust feature. For example, you can allow access to [sensitive application] only from devices that Endpoint Security reports as compliant.

This is Zero Trust in practice. Access depends on who the user is and the state of their device, not only on where the traffic comes from.

How to get started

Enabling Identity Sharing takes one click. In the Identity and Trust portal, click Connect next to the relevant product or enable it from the Integrations wizard. That's it.

 

Have questions or a scenario you want to discuss? Share it in the comments. My team and I are here to help.

Thanks,
Royi Priov
R&D Group manager, Identity and Trust (formerly known as Infinity Identity)
0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events