Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Patrickc
Explorer

Check Point Remote Access Integration with Azure AD MFA

HI All,

The customer currently has a requirement for two-step verification when connecting through Endpoint Security VPN. The first step requires entering the on-premises AD username and password, and the second step involves integrating Azure AD's MFA, using Microsoft Authenticator to enter a token. Is this achievable?

 

GW:R81.20

 

Thanks

0 Kudos
11 Replies
George_Casper
Collaborator

Do you have sync enabled between on-prem AD and Azure AD?

 

0 Kudos
Patrickc
Explorer

Hi George,

Yes

0 Kudos
George_Casper
Collaborator

So long as users and passwords are sync'd you can configure SAML auth directly to Azure AD.    There are two ways to hit Azure AD, one directly with SAML, the other with standing up a RADIUS server in the middle.   We chose the SAML method, less moving parts.   Depending on your M365 license levels you can add also on conditional access policies.

0 Kudos
Patrickc
Explorer

Hi George,

I want to use SAML for authentication. Could you please provide the setup method and steps?

0 Kudos
the_rock
Legend
Legend

Maybe this guide would help?

Andy

0 Kudos
Patrickc
Explorer

Hi Rock,

Can I use Check Point without the NPS Extension for Azure MFA? Is it possible to integrate using Check Point’s IDP object via SAML?

0 Kudos
the_rock
Legend
Legend

I think so.

0 Kudos
George_Casper
Collaborator

We went with SAML as mentioned above, less moving parts.   Though I've read here on previous posts there may be a couple Checkpoint SMB models that may not support SAML depending on what you have.

Patrickc
Explorer

Hi George,

I am using the Check Point 3800 appliance, not the Check Point SMB

0 Kudos
George_Casper
Collaborator

See sk172909 for SAML config though I think there's a better SK if I remember gave better step by step  instructions.

 https://support.checkpoint.com/results/sk/sk172909

(1)
the_rock
Legend
Legend

Thats it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events