Configure Entra ID Remote Access VPN support

Set up remote access VPN identity to support Entra ID (formerly Azure AD)-authenticated users and groups.

This task allows you to leverage Entra ID for remote VPN user authentication and group mapping, enabling advanced access control policies.

Before you begin

Note

Use the same Azure tenant for the Azure SSO object and the Azure AD realm. If these configurations do not match, users can authenticate successfully but do not receive the group data that is required for identity-based access control.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, register the Smart License.

Confirm that the target Firewall Threat Defense device is licensed for remote access VPN.

Step 2

Create the Azure SSO object with the Identity Provider (IdP) and service provider details that Azure AD requires. For information, refer to Add a Single Sign-On server.

Note the Entity ID identifier value.

Step 3

Configure or edit the remote access VPN connection profile to use SAML authentication, as discussed in Create a new Remote Access VPN Policy.

Note

Use the Entity ID value (Azure SSO object) as the connection profile name so the profile matches Azure AD SAML configuration. This is essential for proper authentication of users.

Select the Azure SSO object as the authentication server for the connection profile.

Step 4

Create a SAML Azure AD realm as discussed in Create a Microsoft Azure AD (SAML) Realm

Step 5

Configure Access Control Rules: Open the access control policy and add or edit a rule as discussed in Create and edit access control rules.

On the Users tab, select the Azure AD users or groups that matches the rule.

Step 6

Deploy the configuration changes to the managed Firewall Threat Defense device.


What to do next

Verify the configuration as discussed in Verify the Microsoft Entra ID RA VPN configuration