Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SAML support for SSL VPN

When will Sophos come out with Support for SAML?

The majority of the players out there do support SAML2, why is Sophos dragging its feet.



Edited TAGs
[edited by: emmosophos at 7:48 PM (GMT -7) on 7 Jul 2022]
[locked by: emmosophos at 7:05 PM (GMT -7) on 27 Sep 2022]
Parents
  • Hi,

    please provide a list of the majority of players rather than generic statements.

    Ian

  • Cisco ASA for example - About SSO and SAML 2.0

    and SAML SSO resolve disconnect problems after sleep PC. Today, if PC goes to sleep my ssl vpn session will be destroyed. This is not convenient if 2fa is on. But, I can configure cisco asa, anyconnect and idP to automatically reconnect vpn because the sso token remains valid some time. Without SSO I have to enter password+2fa every time to reconnect

    And thanks to the centralized idP, you can use a single 2fa code (or another protocols, for example: fido2) with all the applications integrated into it. This is much safer than 100500 programs, policies and 2fa codes

  • Looking into the ZTNA Market, Sophos already supports SAML via Azure AD and OKTA. And this is actually the future. 

    If IT Security is your focus (which should be) you should take a look into the ZTNA Market instead. 

  • Looking into the ZTNA Market, Sophos already supports SAML via Azure AD and OKTA.

    Where is Sophos XG SSL VPN support SAML? Please send link/screenshot/example/etc. I use keycloak and I want to try.

    If IT Security is your focus (which should be) you should take a look into the ZTNA Market instead. 

    If IT security is your focus (which should be), you should start by having a single account provider for all your services over OIDC or SAML. Identity providers aka idP (for example: keycloak, ADFS, authentik, ory hydra, etc) resolve this point

    zero trust network access - too broad and redundant in the context of the first question

Reply
  • Looking into the ZTNA Market, Sophos already supports SAML via Azure AD and OKTA.

    Where is Sophos XG SSL VPN support SAML? Please send link/screenshot/example/etc. I use keycloak and I want to try.

    If IT Security is your focus (which should be) you should take a look into the ZTNA Market instead. 

    If IT security is your focus (which should be), you should start by having a single account provider for all your services over OIDC or SAML. Identity providers aka idP (for example: keycloak, ADFS, authentik, ory hydra, etc) resolve this point

    zero trust network access - too broad and redundant in the context of the first question

Children