Microsoft ADFS
Use these instructions to configure the SSO Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications. authentication with Microsoft ADFS Active Directory Federation Services. A Microsoft software component for Windows Server OS to give users single sign-on access to an organization's systems and applications..
-
In the ,Infinity Portal, go to > Identity & Access > click the plus icon.
-
Enter a name for the Integration Title and select ADFS.
-
Click Next.
In this step of the IdP Integration Wizard, you can configure SSO authentication for Infinity Portal administrators and for end users of Check Point services.
-
Select Enable Administrators to log in to the portal using this IdP.
-
Select one of these options:
-
Login based on domain verification - Infinity Portal Administrators can log in to this Infinity Portal account with SSO from the Identity Provider A system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Acronym: IdP or IDP.. Administrators log in through the Infinity Portal login page.
-
Login with a unique URL - Infinity Portal Administrators can log in to multiple Infinity Portal accounts with SSO from the Identity Provider. Administrators log in using the URL that appears at the bottom of the Login with a unique URL button. Copy this URL and keep it in a safe place.
-
-
In the Service(s) Integration section, select one of these options:
-
No Services - End users of Infinity Portal services cannot authenticate with SSO from the Identity Provider. This is the default configuration.
-
All Services - End users can log in with SSO from the Identity Provider to all Check Point services that support SSO.
-
Specific Service(s) - From the list of services, select service(s) to allow end users to log into with SSO from the Identity Provider. Available services:
-
Harmony Connect
-
Quantum Gateways
-
-
-
Click Next (or, if you are editing a configuration, Apply) to complete the Integration Type configuration.
|
Note - If for Integration Type you selected "Login with a Unique URL", the Verify Domain step is not necessary. |
-
Connect to your DNS server.
-
Copy the DNS Value from the Infinity Portal IdP Integration wizard > Verify Domain step.
-
On your DNS server, enter the Value as a
TXT
record. -
In the Infinity Portal > Domain(s) section, enter a public DNS domain server name and click the plus icon.
Check Point makes a DNS query to verify your domain's configuration.
-
Optional - add more DNS domain servers.
-
Click Next.
Note - Wait until the DNS record is propagated and can be resolved.
|
Important - Keep the Infinity Portal and Microsoft ADFS open during all steps of this procedure. |
-
In Microsoft ADFS, navigate to ADFS > Trust Relationships > Relying Party Trusts.
-
From the Actions toolbar on the right > Relying Party Trusts section, click Add Relying Party Trust.
The Add Relying Party Trust wizard opens.
-
In the Welcome step, click Start.
-
In the Select Data Source step:
-
Select Enter data about the relying party manually.
-
Click Next.
-
-
In the Specify Display Name step:
-
Copy the Display Name from the Infinity Portal and paste it in the Display name field in Microsoft ADFS.
-
In Microsoft ADFS, click Next.
-
-
In the Configure Certificate step, click Next. Do not upload a token encryption certificate.
-
In the Configure URL step:
-
Select Enable support for the SAML 2.0 WebSSO protocol.
-
Copy Replying party SAML 2.0 SSO service URL from the Infinity Portal to the field with the same name in Microsoft ADFS.
-
Click Next.
-
-
In the Configure Identifiers step:
-
Copy the Relying party trust identifier from the Infinity Portal and paste it in the Relying party trust identifier field in Microsoft ADFS.
-
Click Next.
-
-
In the Choose Access Control Policy step:
-
Select permit everyone.
-
Click Next.
-
-
In the Ready to Add Trust step, click Next.
-
In the Finish step, click Finish.
-
In the Microsoft ADFS Relying Party Trusts window, right click on the table row "check point infinity Portal SSO".
-
Click Edit Claim Issuance Policy...
The Add Transform Claim Rule Wizard opens in a new window.
-
In the Choose Rule Type step:
-
For Claim rule template, select Send LDAP attributes as claims.
-
Click Next.
-
-
In the Configure Claim Rule step:
-
For Claim rule name, enter
LDAP Attributes as Claims
. -
For Attribute store, select Active Directory.
-
In the table, add these LDAP Lightweight Directory Access Protocol. It provides a mechanism used to connect to, search, and modify Internet directories (such as Microsoft Active Directory). attributes:
LDAP Attribute
Outgoing Claim Type
User-Principal-Name
UPN
Display-Name
Name
E-Mail-Addresses
E-Mail-Address
User-Principal-Name
Primary SID
-
Click Next.
-
-
In the Finish step, click Finish.
-
In the Microsoft ADFS Relying Party Trusts window, right click on the table row "check point infinity Portal SSO".
-
Click Edit Claim Issuance Policy...
The Add Transform Claim Rule Wizard opens.
-
In the Choose Rule Type step:
-
For Claim rule template, select Send Group Membership as a Claim.
-
Click Next.
-
-
In the Configure Claim Rule step:
-
For Claim rule name, enter
LDAP Attributes as Claims
: -
For Attribute store, select Active Directory.
-
In the table, add this LDAP attribute:
LDAP Attribute
Outgoing Claim Type
Token Groups - Unqualified Names
Group SID
-
Click Next.
-
-
In the Finish step, click Finish.
-
Restart the ADFS services or restart the server on which ADFS is running to apply the configuration.
-
In the Infinity Portal > Allow Connectivity step, click Next.
-
Download the ADFS Federation Metadata file from:
https://<your-domain>/FederationMetadata/2007-06/FederationMetadata.xml
-
In the Infinity Portal > Configure Metadata page, upload the Federation Metadata XML that you downloaded from your ADFS.
Note - Check Point uses the service URL and the name of your Certificate from the metadata file to identify your users behind the sites.
-
Click Next.
Review the details of the SSO configuration and click Submit.
|
Important - Before you log out of the Infinity Portal, create a user group with the applicable roles and assign it to the related IdP group name or ID. For more information, see User Groups. |