GP internal gateway for Azure AD authenticated users

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GP internal gateway for Azure AD authenticated users

L0 Member

In our on-prem firewalls, some policies are based on user-ID.

User-to-IP mapping for the corresponding users are sourced via different mechanisms such as;

 - User-ID agents installed on domain-controllers

 - terminal server agents.

This setup has been working pretty well so far.

However, now we have a challenge after the introduction of Microsoft "modern devices". Users logged in to these devices are authenticated against Azure AD instead of the on-prem AD servers. Because of this, on-prem firewalls are unable to acquire any user-to-IP mapping information. To address this problem, we are looking at deploying GP internal gateway on modern devices hoping that it can provide the required mapping information to the firewall. However, we have some unknowns about this approach.

 

  • How to authenticate clients when connecting to the internal gateway

When a GP client connect to the internal gateway, firewall needs to authenticate it first.

This authentication need to be seamless  as the user already authenticated to the device already.

We have the options of certificate authentication or SAML ( by communicating with Azure AD )

 

  • Even after this authentication, we are not sure what the format of the username populated in the firewall along with the IP address.

Since the user is authenticated against the Azure AD, we have a suspicion that the UPN (i.e. the email address ) will be populated as the username instead of the sAMAccountName (ie. Domain/username format)

If the UPN is populated as the user name, the firewall will not be able to use it any of the policies as the firewall is not integrated with Azure AD.

In that case, we will have to the cloud-ID-engine function as well to pull Azure-AD group mapping

 

Just wondering whether anyone has implemented a similar solution ?

Apologies for the lengthy message.

0 REPLIES 0
  • 685 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!