This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
  • Just took a quick look into this case. You never mentioned before, you are using only VM´s with RDP connected to them. So i tried to reproduce this issue with a VM and only RDP to this. But my Client is shown under Live User. 

    Client is 2.2.2 Core agent. 

    .local Domain. 

     

    Still not sure, what is happening in your case, so i would recommend to debug this with Sophos Support. 

  • A quick update on this.

    I was asked by Sophos Support to try using LDAP instead of AD. Although this also failed, for the first time, there was an entry in the Authentication Log, to confirm failure.

    Unlike when I login with Captive Portal for same user, it records the UPN login, the failure with LDAP shows just the bit before the @

    So, I guess its a bit pf progress, although am told now LDAP will not work.

  • I have success!!!


    So this is what I did precisely


    1) Tested with LDAP - failed
    2) Re-installed Endpoint
    3) Tested with LDAP - failed
    4) Change back to AD for authentication
    5) Deleted the user (have done this a few times before)
    6) Logged in once more and after a few minutes - success

    So, I guess a combination of re-installing Endpoint, removing user and changing back from LDAP to AS authentication seems to have resolved the problem. Not conclusive, but hopefully helps someone.

    Continue to test repeatedly and will post results here

  • Least you do have it working now, I did suggest you try starting out fresh where your Authentication on XG is setup.  But like the saying goes if its not broke dont change it (well along those lines i think it goes)  As to the part about it not working WITH LDAP i think that needs to be reworked on the KB article as thats how i got my Heartbeat Auth to work wasnt it,  As long as its LDAP on an AD DC it works.

    I know its been said here already that you dont need Sophos Central AD Sync in place for it too work but i found it definitely helped having that in place to start with.  It mean i was pretty sure i had my UPN's setup right.

    But congrats, on persevering.

  • Hello Paul Digby and Michal Bartos,

    maybe I know where could be the problem with your Authentication. We have verified that sAMAccountName and UPN in Microsoft Active Directory have to be identical to make a login and  Authentication successful.

    Could you please check in your Microsoft Active Directory in User properties  - Attribute Editor. Should be enabled Advanced Features in View submenu and in the Attribute Editor two Filters - "Show only attributes that have values" and "Show only writtable attributes". At the first screen are the sAMAccountName and the UPN the same and an Authentication is successful. At the second screen are the sAMAccountName and the UPN different and an Authentication is unsuccessful.

     
    Could you please verify this suspicion in your Microsoft Active Directory environment? We have opened for this case a ticket at the Sophos support. In our opinion, this is an implementation error, because sAMAccountName may not always be identical to UPN name. We would like to verify our suspicion of a bug in the implementation of authorization in the Sophos Central end-point client.

    Thank you in advance and regards

    alda

  • For me, this is working now, I believe after re-installation of Endpoint.

    I can confirm that sAMAccountName is the same as UPN as you show in image above on the left. So my experience does not confirm your suspicion, but I think that you are correct.

  • Hello,

    My sAMAccountName and username part of UPN are identical.

    I've found out, our problem is with the suffix part of UPN, because we have two.

    Thanks.