Microsoft Azure AD
How to Configure the SSO Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications. authentication with Microsoft Azure:
Prerequisite: Create an Enterprise Application on the Azure Portal
Add Check Point's Infinity Portal application in the Azure Portal:
-
Sign in to the Azure portal with a work or school account or a personal Microsoft account.
-
On the left navigation pane, select the Azure Active Directory
Microsoft® directory information service. Stores data about user, computer, and service identities for authentication and access. Acronym: AD. service.
-
Navigate to Enterprise Applications and select All Applications.
-
To add a new application, select New application.
-
In the Add from the Gallery section, enter Check Point Infinity Portal in the search box.
-
Select Check Point Infinity Portal from the results panel and add the app. The app is added to your account.
Step 1: Select IdP and Title
-
In the Infinity Portal go to Global Settings > Identity & Access > click the plus icon.
-
Select Azure AD.
-
Click Next.
Step 2: Verify your Domain
-
The DNS record generates. Click to copy the generated DNS record value
-
Enter the copied DNS record to your DNS server as a
TXT
record. -
Below Domain(s), enter your organization's domain and click the plus icon.
Check Point makes a DNS query to verify your domain's configuration.
-
Click Next.
Note - Wait until the DNS record is propagated and can be resolved.
Step 3: Configure Check Point's Infinity Portal Application in the Azure Portal
-
In the Allow Connectivity page, copy the Entity ID and the Reply URL.
-
In the Azure portal, on the Check Point Infinity Portal application integration page, in the Manage section select single sign-on.
-
On the Select a single sign-on method page, select SAML.
-
On the Set up single sign-on with SAML page, click the pencil icon to edit the settings for Basic SAML
Security Assertion Markup Language. An XML-based, open-standard data format for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. Configuration.
-
On the Basic SAML Configuration section, do these steps:
-
In the Identifier text box, paste the copied entity ID.
-
In the Reply URL text box, paste the previously-copied Reply URL.
-
In the Sign on URL text box, paste the previously-copied Reply URL as well.
-
-
On the Set up single sign-on with SAML page, in SAML Signing Certificate, find Federation Metadata XML and select Download to download the XML file.
-
When the download is done, go to the Check Point Infinity Portal and click Next.
Step 4: Configure Check Point Infinity Portal Application User Roles
Use one of these options:
-
Option 1: Configure Check Point Infinity Portal application user roles in Azure AD portal.
Create Admin and "
readonly
" roles in the Azure portal.-
From the left pane in the Azure portal, select App Registration > All applications > Check Point Infinity Portal application.
-
From the left pane, select App roles, click Create app role and do these steps:
-
In the Display name field, enter Admin.
-
In the Allowed member types, select Users/Groups.
-
In the Value field, enter admin.
-
In the Description field, enter Check Point Infinity Portal Admin role.
-
Make sure Enable this app role is selected > click Apply.
-
Click Create app role.
-
In the Display name field, enter
readonly
. -
In the Allowed member types, select Users/Groups.
-
In the Value field, enter
readonly
. -
In the Description field, enter Check Point Infinity Portal Admin role.
-
Make sure to select Enable this app role.
-
Click Apply.
-
-
-
Option 2: Configure Check Point Infinity Portal application user roles in Check Point Infinity Portal.
This configuration is only for groups assigned to the Check Point Infinity Portal application in Azure AD. In this section, create one or more User Groups that hold the Global and Service
A Check Point service offering that helps customers with deployments or technical services for Check Point products. roles for the applicable Azure AD groups.
-
Copy the ID of the assigned group for use with the Check Point Infinity Portal User Group IdP ID field.
-
For User Group configuration, see User Groups.
-
Select applicable users and groups:
Configure the users and groups that are allowed to authenticate by Azure AD when you use the Check Point Infinity Portal.
-
When you edit your enterprise application in the Azure Portal, navigate to Users and Groups.
-
Add all groups or all individual users with related roles configured in section 11 above, if applicable.
-
-
Step 5: Configure Metadata
-
In the Configure Metadata page, upload the Federation Metadata XML that you downloaded before from your Azure AD.
Note - Check Point uses the service URL and the name of your Certificate to identify your users behind the sites.
-
Click Next. Check Point validates your Identity Provider
A system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Acronym: IdP or IDP.'s metadata of your Identity Provider.
Step 6: Confirm Identity Provider Integration
Review the details of the SSO configuration and click Submit.
|
Important - Create a user group with the applicable roles and assign it to the related IdP group name or ID. This depends on the applicable identity provider before you log out. For more information, see User Groups. |