Hello everyone,
I am currently working on a PoC for a customer to implement SAML and MFA for their Mobile Access Portal. This part, I was able to get to work in my lab but I am having trouble understanding how to adapt the Mobile Access Policy. This is about the only customer I know using Mobile Access with Application Access via SNX and since they mainly manage it themselves, I am not quite knowledgeable on this topic.
Currently they are using the Legacy Policy in SmartDashboard. From what it seems, users are authenticated to Applications via RADIUS.
Now during the SAML configuration, I had to add an External User Profile named generic* in SmartDashboard and add this profile/user to the group specified as the source in the Mobile Access Policy in SmartDashboard. Without the generic* user in the policy/group, I was not able to authenticate via SAML.
Now this brings up a few questions, since adding the generic* user to every group/rule would allow any user to access any application.
- Do I misunderstand how the policy works? Is there still a way to only allow access to certain applications to certain users?
- I tried to switch to Unified Access Policy but Access Roles using Azure AD are not allowed in a rule with a Mobile Access Application. Is there a workaround?
I'm sure I am missing something here, because it doesn't really make sense to me...
Thank you and best regards