- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi Mates,
I have configured Azure saml authentication for remote access vpn. During testing, We are getting "Negotiation with site is failed" error message on client side and "user does not belong to remote access community" in smart console.
When I changed remote access vpn community participating group to "all user", we are able to authenticate for remote vpn using saml.
Question here is, can I map Azure identity provider group in remote access community participating group? because it does not show any identity provider group when I try to add in participating group. Or I need to keep "All user" in participating group?
I attached a doc that hopefully is helpful to you.
Andy
Create groups as described here: https://support.checkpoint.com/results/sk/sk177267
Thanks, Phoneboy. I have already created and tested with group name EXT_ID_ with no luck. I will verify configuration with Azure administrator.
The sk Phoneboy gave you is definitely good place to start. One of my colleagues and I had to do this for a large customer.
Thanks @the_rock for sharing document. I will verify.
Hope it really helps you, as we always follow it and works fine. Let me know if any issues.
We have followed sk177267 & sk172909 to define group in Azure. Still, it was not working, Lastly, we have configured each group has its own role which you mentioned in supplementary instruction document (Undocumented step – CRUCIAL). It did the trick. Now it is working as expected.
Thanks again for sharing supplementary instruction document.
I agree, thats super important step. My colleague and I got that from Azure documentation, I will write a feedback about it in the sk.
Best,
Andy
Okay, just submitted a feedback.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY