This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Questions about Azure MFA / NPS and group membership

Hey together, 

I've configured our NPS according the tutorial from twister5800 https://community.sophos.com/xg-firewall/f/recommended-reads/122575/sophos-xg-using-azure-mfa-for-ssl-vpn-and-user-portal/451795#451795 . 

The general authentication is working but I have several configurations issues. Maybe somebody can assist.

- The authentication is only working if I switch to "Accept user without confirming their credentials" instead of "Authenticate requests on this Server". Otherwise the autentication fails. The NPS is installed at a domain controller. 

- How can I control the group membership of the users? If I login at the user portal, they user is dropped to the default group at XG.  

- If I login with the upn at the user portal, the user is created without the domain ending. Like max.mustermann instead of max.mustermann@company. 

This is not happening if I login with he the regular active directory login,where the user is created with full upn. 

Happy for any support.



This thread was automatically locked due to age.
Parents
  • Hi Jonnie,

    First of all you need to go back an enable this:

    "Authenticate requests on this Server"

    Then I would advise to go through the whole guide again, and add special attention to each and every setting :-)

    Then if it's still not working, share some screenshots form the XG and NPS :-)

    I presume that you have tested RADIUS from XG is working?

    regadring the group, add it here:

    Are the users loginname in your AD also the full UPN or something like .local??

    Let's take it from here :-)

  • Hey Martin, 

    glad to hear from you! Slight smile  

    I switch the authentication method back to the default value and now I can login. Can't explain why it is now possible. I had read your tutorial the weekend more than once. But the first login with a user which has never seen by the xg, needs two login attempts? Is this intentional?

    Beside that, the user has set it's public email adress at AD but the XG use only name.surname for the username. 

    Yes I already matched the network policy to a group at AD, but how can I match the user and group at XG ? We have several groups at the XG which belongs the different permission sets.  

Reply
  • Hey Martin, 

    glad to hear from you! Slight smile  

    I switch the authentication method back to the default value and now I can login. Can't explain why it is now possible. I had read your tutorial the weekend more than once. But the first login with a user which has never seen by the xg, needs two login attempts? Is this intentional?

    Beside that, the user has set it's public email adress at AD but the XG use only name.surname for the username. 

    Yes I already matched the network policy to a group at AD, but how can I match the user and group at XG ? We have several groups at the XG which belongs the different permission sets.  

Children