Web Security Services

  • 1.  Cloud SWG SAML Integration with Azure AD

    Posted Aug 02, 2024 03:05 PM

    Hello,

    I am trying to integrate Cloud SWG with Azure AD in my lab. The Cloud SWG is managed by management center.  The agents are sep clients in tunnel mode. I have the below issues.

    1. When I configure the authentication policy for Agents and SEP client to use SAML then the sep-client shows the user a microsoft login page. Is this expected?. Is there a way to transparently identify the user instead of showing them a login page?.
    2. Should I sync the users from Azure AD to cloud SWG or there is no need as I am using the management center to push policies to cloud SWG?

    If anyone has done it before, kindly advise.



  • 2.  RE: Cloud SWG SAML Integration with Azure AD

    Posted Dec 18, 2024 05:18 PM

    Hello,

    It's actually pretty easy.

    For sealmess sso to work, you need the following:

    The same domain name on AD and Azure.

    You need to exclude the autologon.microsoftazure-sso.com from SSL interception.

    You need autologon.microsoftazure-sso.com to be in your "Local Intranet" settings in "Internet Options"