Remote Access VPN for Microsoft Entra ID-authenticated users
Microsoft Entra ID (formerly Azure AD) remote access virtual private network (RA VPN) support lets Secure Firewall use Microsoft Entra ID-authenticated VPN sessions for identity-aware access control. After a user signs in through Security Assertion Markup Language (SAML), the system enriches the session with realm and group information so Snort can enforce access control rules based on Entra ID users and groups.
Guidelines for configuring RA VPN Entra ID support
-
Create an Azure SSO object for SAML authentication.
-
Create an Azure AD realm using the same Azure tenant as your Azure SSO object.
-
Enable Dynamic Attributes Connector when Cloud-Delivered Firewall Management Center prompts you during realm creation.
-
You do not need to attach a separate identity policy for access control because identity is available when the VPN session is established and enriched.