Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dave_vz
Explorer

windows identity agent with entra groups for authorization

hi 

i have a question.

we are using identity agent on windows with sso towards the ad domain.

this works ok.

we can create access roles that reference ad groups and this also works

we are also using entra.

i would like to know if i can mix them together

so get the identity of the user via the identity agent on the pc (this works)

and match this with a entra group to deliver the authorization.

i configured entra with succes, but in my testing i see no match happening between this combination

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Groups in LDAP (for on-premise AD) versus groups in SAML (i.e. Entra ID) are handled and represented differently.
As a result, there is no way to correlate between the two.

Entra ID groups (passed to the gateway via the SAML assertion) can be used in policies, but they must be explicitly defined.
See: https://support.checkpoint.com/results/sk/sk177267 

Having said that, @Royi_Priov is this something that Identity and Trust allows for?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events