Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XGS and AD sync

Hello,

Have 2 questions related to user authentication. 

1. Do we know the sync interval between Sophos XG and Active Directory. .We have disabled few users from AD, however they are still able to authenticate against Sophos Firewall via a captive portal. ?

2. Captive portal allowing to authenticate users who are not part of the 'allowed' user group - We have set up a BYOD  network and added few user groups to it. however noticed that users which are not part of those user groups can type in their username and password  in captive portal without any error. What we expect is that captive portal should pop up an error message saying - ' User cannot be authenticated as it is not part of allowed User groups' or something similar' 



This thread was automatically locked due to age.
Parents
  • Hi : Thank you for reaching out to the Sophos community team.

    1)The users which you have disabled on AD, the same users have been disabled on XG inside user sections as well manually? if not then please disable the same and confirm the status.

    Step: to Authentication > Users > Select User > Click Change status.

    2) For point 2 below is the suggestion that you may check and try if that one fulfills your actual requirement:

    Once you integrate AD, any active AD user will be able to authenticate over XG. To limit the Internet request for an unwanted group please ensure that no matching rule there in the firewall rule to allow Internet for that user group OR if the matching rule is there for that group then please ensure that the rule action selection drop to prevent Internet traffic. 

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • 2) For point 2 below is the suggestion that you may check and try if that one fulfills your actual requirement:

    Once you integrate AD, any active AD user will be able to authenticate over XG. To limit the Internet request for an unwanted group please ensure that no matching rule there in the firewall rule to allow Internet for that user group OR if the matching rule is there for that group then please ensure that the rule action selection drop to prevent Internet traffic. 

    Comment: Yes traffic is blocked for unwanted users as their group is not part of allowed one's

    However what we need is - Users  to be told by a message they dont have access at the captive portal level rather than users signing in and later  finding it out.  Is that a feature request ?

    1)The users which you have disabled on AD, the same users have been disabled on XG inside user sections as well manually? if not then please disable the same and confirm the status.

    Step: to Authentication > Users > Select User > Click Change status.

    Comment: Is there any way to automate this one rather than manual. As customer needs to disable few users on a daily basis and enable it back.  i was under the impression that XG will make a request to AD when a user makes  a request for authentication[ FYI- there is no STAS involved ]

  • There is no sync with AD in any period of time.

    Instead the data will be fetched by each and every login. So to speak, if you disable a user, the user should not be able to use any facility anymore in SFOS as well, as AD should deny the request.

    Please verify, you do not have "local" activated on authentication - services. This would mean, SFOS is using the local cred store as well. 

    __________________________________________________________________________________________________________________

Reply
  • There is no sync with AD in any period of time.

    Instead the data will be fetched by each and every login. So to speak, if you disable a user, the user should not be able to use any facility anymore in SFOS as well, as AD should deny the request.

    Please verify, you do not have "local" activated on authentication - services. This would mean, SFOS is using the local cred store as well. 

    __________________________________________________________________________________________________________________

Children