Configure SSO JIT Provisioning with ADFS

With JIT provisioning, users log in to ADFS with their ADFS credentials and select to log in to CloudGuard configured as an SSOClosed Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications. application. SAML authenticates the credentials and transfers them to CloudGuard to create users based on their email address and AD group membership that are mapped to the existing CloudGuard roles.

Configuring Active Directory

To map dynamically AD groups to CloudGuard roles, create AD groups with CloudGuard or other relevant prefix (for example, CG-Admins, CG-Users). Add users to these AD groups. Check Point recommends to add a user to only one CloudGuard AD group.

Configuring ADFS

On the ADFS side, ensure that you have a working ADFS configuration. For this, log into the main page

https://<server.domain.com>/adfs/ls/idpinitiatedsignon.htm

where <server.domain.com> is your ADFS WAP server. If you need a valid SSL certificate, you can get one for free from Let’s Encrypt.

Then you need to add CloudGuard as a Relying Party Trust to be a consumer of the ID provider.

Configuring CloudGuard

When you continue in CloudGuard, log in with your super user credentials.

Testing ADFS Single Sign-On