- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hello Everyone,
I have a requirement to enforce user based policies in checkpoint firewall with Azure AD. We have integrated the Azure AD with checkpoint firewall (MGMT server in S1C). I able to view the users when creating the access roles but policy enforcement is not happening during the traffic.
At the same time, i don't want captive portal authentication from firewall. since already user did multiple authentication to connect the network. If transparent authentication is possible please suggest.
Does any one have solution kindly help me on this.
Note: I don't have any Domain controller.
Thanks
Rajkumar T
For Identity Awareness to work correctly with Azure AD, Captive Portal is required.
See: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide...
Without this, the gateway cannot see the authentication and authorization information, which is otherwise encrypted via TLS.
This will be transparent to users.
Hi @PhoneBoy ,
My case i don't need any authentication for the users, So can i enable the SSO with SAML ?
Is it required any IDP.
Thanks
Rajkumar T
In SAML terms, Entra ID is an Identity Provider and the Check Point Firewall is a Service Provider.
When everything is configured correctly (including enabling Captive Portal), the Firewall will see the authentication with Entra ID and authorize the user with specific Access Roles or tags configured.
It doesn't require a separate authentication step for the end user.
If you have multiple gateways and/or also using Entra ID to authenticate Remote Access VPN users, you should consider the Identity and Trust offering mentioned by @Royi_Priov as it simplifies the configuration substantially.
Hi Phoneboy,
I have configured everything clearly. but still traffic not matching with user based policies.
I got captive portal redirected log, and user not getting an internet. Attached some snaps for your reference. Kindly guide me if any other steps needed.
To use Royi's solution we need separate license i guess, so it will helps me.
Thanks
Rajkumar T
Aside from Captive Portal, what exactly have you tried to configured to support this requirement?
This should include set up in Entra ID.
Hi @TRajkumar
The proper way to allow SSO with Entra ID is with Check Point Identity and Trust (formerly known as Infinity Identity).
Identity and Trust gets the IP to identity association from both Microsoft Intune and Defender.
Please read more about it here:
https://www.checkpoint.com/resources/items/solution-brief-check-point-identity-and-trust
If you have additional questions, please let me know.
Hi Royi,
I Hope this requires additional license.
Thanks
Rajkumar T
Hi @TRajkumar
yes it does. It is part of the AI package (premium and complete).
You can start a 60-day trial in the portal on your own.
If you need, please PM me to grant you a trial license (if you have already passed the 60 days).
Hi Mate,
I have also facing the same requirement and I have few queries below
- How Azure AD is connected to Checkpoint?
- In Azure are you using Microsoft Entra or Azure VM where Windows Server with AD configured in it?
- If Azure VM how you connect Azure VM with Checkpoint, is it using VPN?
- And finally is your requirement completed?
Regards,
Saranya
Hi Saranya,
My requirement is not closed.
- How Azure AD is connected to Checkpoint? - Created the Non-gallary application on Azure portal
- In Azure are you using Microsoft Entra or Azure VM where Windows Server with AD configured in it? - I'm using Entra AD
- If Azure VM how you connect Azure VM with Checkpoint, is it using VPN? - No
- And finally is your requirement completed? - No
Do let me know if you have answer.
Thanks
Rajkumar T
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY