- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-16-2025 08:58 AM
Hello
we are using SCM for our NGFWs and try to connect via Global Protect.
Using Radius Auth we can login with any client/os we those, but we want only domain joined device (w11,ios,ipad) to be connected via VPN.
Where we must configure SCM to look at M365 for company devices?
Kind regards
09-16-2025 09:20 AM
There's a lot of different ways to accomplish what you are looking for. You could make a machine certificate check against a certificate profile if you're issuing out machine certs, setup a custom check against a registry key like
09-17-2025 12:14 AM
We have activate certificatprofil in the agent-app configuration, but this only stops windows client company/private to connect, iPad company/privat can connect. Or where we must set the agent app certificatprofile with our ROOT and ISSUNG CA?
Registry would only help againt Windows, at the moment we distribute the GP IP/FQDN with registry GPO
We had a HIP rule after the GP connect rule but it wasen't used or HIT-Count dosen't grow and we don't see any HIP-Match in Monitor on the local FW.
Or did we use HIP wrong?
I'm not really familiar with SAML, but i ask my support if he done this befor on local configurations
Kind regards
09-17-2025 01:51 AM
We have found the first issue, Radius Auth was in "user OR client zertifikat" mode not both.
For the moment we can work with this, but if someone copy the certificats to his privat device it is a new corporate device.
But now the corparate iPad won't connect, RootCA is visible under configuration and ISSUING is rolled out over intune but it won't connect
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!