- CheckMates
- :
- Products
- :
- Harmony
- :
- SASE
- :
- Harmony Connect App and Identity Awarness
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Harmony Connect App and Identity Awarness
Hello,
What is the point of Identity Awareness feature for Harmony Connect App Remote Users? We use Azure AD as IDP in Harmony Connect and we noticed the same behavior regardless of Identity Awareness enable status, that is, we can filter access trough Network Access policy based on Azure AD groups and users, usernames appearing in logs, etc...
From Admin Guide I understood that when Identity Awareness is enabled it should ask users for credentials before connecting to Harmony Connect cloud, but is this meant only for clientless users and not for Connect App users then?
Best Regards,
Igor
- Labels:
-
corporate access
-
Internet Access
-
SASE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you clarify the scenario?
Remote Access (Network Access) to internal resources?
-or-
Internet Access (WWW) to external resources?
The latter is explained here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, I meant both use cases, actually... But even for the Internet access case, I would like to get some clarification about what is stated in the config guide, is the expected flow like this (in case Identity Awareness is enabled)?:
- If the Connect App end user is not authenticated, when the client tries to access Internet or Internal resources (Network Access feature) browser should pop-up to do SAML with IDP (Azure AD).
- The user is authenticated and the traffic will be matched by security policy referencing Azure group/username in the Source column.
- Traffic is logged with client username as an addition to IP address
Regards,
Igor
