Configuring a Centralized Identity Provider

In R82 and higher, you can centrally define one or more Identity Providers (IdP), such as Microsoft Entra ID and Okta within Check Point Portal. These IdP configurations can then be reused across multiple Security Gateways using SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. that have the Identity AwarenessClosed Software Blade on a Check Point Firewall that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. Blade enabled.

How Centralized IdP Works

  • You configure your IdP once in the Check Point Portal.

  • The IdP is then available as a read-only object in SmartConsole.

  • Security Gateways use this central IdP for user authentication and group membership, enabling Identity Awareness features such as user-based Access Roles and policies.

This example uses Microsoft Entra ID but applies to any IdP supported by the Check Point Portal.

  1. A user defined in Microsoft Entra ID attempts to access Amazon Web Services.

    Note - If you have more than one IdP configured, the user is redirected to the Captive PortalClosed A Check Point Identity Awareness web portal, to which users connect with their web browser to log in and authenticate, when using Browser-Based Authentication. to select an IdP.

  2. Upon successful authentication through the IdP, the user is granted access to Amazon based on your predefined ruleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session..

Limitation

Prerequisites

  • Access to one of these supported cloud platforms.

  • An app on your chosen platform with permissions to create groups and assign users.

  • SmartConsole is connected to the Check Point Portal.

  • Login credentials for Check Point Portal and the IdP.

Supported IdPs

  • Microsoft ADFS

  • Microsoft Entra ID

  • Okta

  • OneLogin

  • Ping Identity

  • Google Workspace

  • Generic SAML Server

Important - Only the EU, US, India and Australia regions are supported in Identity and Trust configurations.

How to Configure a Centralized Identity Provider

Before you begin, log in to SmartConsole, the Check Point Portal, and your IdP.