Configure Entra ID Remote Access VPN support
Set up remote access VPN identity to support Entra ID (formerly Azure AD)-authenticated users and groups.
This task allows you to leverage Entra ID for remote VPN user authentication and group mapping, enabling advanced access control policies.
Before you begin
Note | Use the same Azure tenant for the Azure SSO object and the Azure AD realm. If these configurations do not match, users can authenticate successfully but do not receive the group data that is required for identity-based access control. |
Procedure
Step 1 | In Cloud-Delivered Firewall Management Center, register the Smart License. Confirm that the target Firewall Threat Defense device is licensed for remote access VPN. | ||
Step 2 | Create the Azure SSO object with the Identity Provider (IdP) and service provider details that Azure AD requires. For information, refer to Add a Single Sign-On server. Note the Entity ID identifier value. | ||
Step 3 | Configure or edit the remote access VPN connection profile to use SAML authentication, as discussed in Create a new Remote Access VPN Policy.
| ||
Step 4 | Create a SAML Azure AD realm as discussed in Create a Microsoft Azure AD (SAML) Realm | ||
Step 5 | Configure Access Control Rules: Open the access control policy and add or edit a rule as discussed in Create and edit access control rules. On the Users tab, select the Azure AD users or groups that matches the rule. | ||
Step 6 | Deploy the configuration changes to the managed Firewall Threat Defense device. |
What to do next
Verify the configuration as discussed in Verify the Microsoft Entra ID RA VPN configuration