<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AD SSO Archives - Network Guy</title>
	<atom:link href="https://networkguy.de/tag/ad-sso/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Share your knowledge!</description>
	<lastBuildDate>Sun, 24 Jan 2021 15:54:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://networkguy.de/wp-content/uploads/2016/09/cropped-og-image-32x32.jpg</url>
	<title>AD SSO Archives - Network Guy</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">35051042</site>	<item>
		<title>Sophos UTM AD SSO Proxy does not recognise the ad groups</title>
		<link>https://networkguy.de/sophos-utm-ad-sso-does-not-recognise-the-ad-groups/</link>
					<comments>https://networkguy.de/sophos-utm-ad-sso-does-not-recognise-the-ad-groups/#comments</comments>
		
		<dc:creator><![CDATA[Phillip]]></dc:creator>
		<pubDate>Sun, 24 Jan 2021 15:54:00 +0000</pubDate>
				<category><![CDATA[Sophos UTM]]></category>
		<category><![CDATA[AD SSO]]></category>
		<category><![CDATA[sophos utm]]></category>
		<guid isPermaLink="false">https://networkguy.de/?p=2538</guid>

					<description><![CDATA[<p>Hello guys, I have had a ticket for a long time, which I was finally able to solve. The screenshots are from my test lab. The log entries are partially anonymised. &#160; The problem The problem was that a customer wanted to use AD SSO in his secondary location. The secondary location has a RODC. [&#8230;]</p>
<p>The post <a href="https://networkguy.de/sophos-utm-ad-sso-does-not-recognise-the-ad-groups/">Sophos UTM AD SSO Proxy does not recognise the ad groups</a> appeared first on <a href="https://networkguy.de">Network Guy</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Hello guys,</p>
<p>I have had a ticket for a long time, which I was finally able to solve.</p>
<p>The screenshots are from my test lab. The log entries are partially anonymised.</p>
<p>&nbsp;</p>
<h4><strong>The problem</strong></h4>
<p>The problem was that a customer wanted to use AD SSO in his secondary location. The secondary location has a RODC. During the setup, we encountered the problem that the proxy did not recognise which AD group the test user was in. As a result, the proxy rules that worked on the basis of AD groups did not apply.</p>
<p>Log entry</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">2020:12:02-17:00:13 Test-UTM httpproxy[6301]: id="0003" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="192.168.88.12" dstip="" user="testuser" group="" ad_domain="SPDNS"</pre>
<p>As you can see in the entry, the user and the domain are recognised. However, not the group.</p>
<h4><strong>what have we check</strong></h4>
<h5><strong>UTM configuration</strong></h5>
<p>First we checked whether the utm can authenticate the user against the AD.</p>
<p><a href="https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check.jpg"><img fetchpriority="high" decoding="async" class="alignnone size-large wp-image-2539" src="https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check-1024x540.jpg" alt="" width="1024" height="540" srcset="https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check-1024x540.jpg 1024w, https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check-300x158.jpg 300w, https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check-768x405.jpg 768w, https://networkguy.de/wp-content/uploads/2021/01/AD-User-Check.jpg 1069w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<p>Now we took a closer look at the proxy configuration.</p>
<p><a href="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-1.jpg"><img decoding="async" class="alignnone size-full wp-image-2540" src="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-1.jpg" alt="" width="954" height="455" srcset="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-1.jpg 954w, https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-1-300x143.jpg 300w, https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-1-768x366.jpg 768w" sizes="(max-width: 954px) 100vw, 954px" /></a></p>
<p>The group &#8220;surfen&#8221;, is a imported AD group. You can the this by the user authentication test screenshot.</p>
<p><a href="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2.jpg"><img decoding="async" class="alignnone size-large wp-image-2541" src="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2-1024x495.jpg" alt="" width="1024" height="495" srcset="https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2-1024x495.jpg 1024w, https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2-300x145.jpg 300w, https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2-768x371.jpg 768w, https://networkguy.de/wp-content/uploads/2021/01/Proxy-Settings-2.jpg 1078w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<p>All OK.</p>
<p>As the last step on the UTM, I checked the AD SSO status.</p>
<p><a href="https://networkguy.de/wp-content/uploads/2021/01/UTM-SSO-Status.jpg"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-2542" src="https://networkguy.de/wp-content/uploads/2021/01/UTM-SSO-Status.jpg" alt="" width="981" height="275" srcset="https://networkguy.de/wp-content/uploads/2021/01/UTM-SSO-Status.jpg 981w, https://networkguy.de/wp-content/uploads/2021/01/UTM-SSO-Status-300x84.jpg 300w, https://networkguy.de/wp-content/uploads/2021/01/UTM-SSO-Status-768x215.jpg 768w" sizes="(max-width: 981px) 100vw, 981px" /></a></p>
<h5><strong>On the RODC</strong></h5>
<p>The UTM had a computer account and all was right.</p>
<p>By chance I came across a netlogon error message in the server manager.</p>
<p><a href="https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B.jpg"><img loading="lazy" decoding="async" class="alignnone size-large wp-image-2544" src="https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B-1024x429.jpg" alt="" width="1024" height="429" srcset="https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B-1024x429.jpg 1024w, https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B-300x126.jpg 300w, https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B-768x322.jpg 768w, https://networkguy.de/wp-content/uploads/2021/01/Server-Manager-SSO-Netlogon-Failure-B.jpg 1451w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<p>After deleting the UTM computer account in the AD and a rejoin, it worked. :D</p>
<p>I suspect that something didn&#8217;t work right the first time I joined the AD. And the second time it finally worked.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Have a nice day!</strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a href="https://networkguy.de/sophos-utm-ad-sso-does-not-recognise-the-ad-groups/">Sophos UTM AD SSO Proxy does not recognise the ad groups</a> appeared first on <a href="https://networkguy.de">Network Guy</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://networkguy.de/sophos-utm-ad-sso-does-not-recognise-the-ad-groups/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2538</post-id>	</item>
	</channel>
</rss>
