Skip to content

Microsoft Entra ID

You can integrate Microsoft Entra ID with Sophos Firewall as an OpenID Connect (OIDC) identity provider (IdP) to provide secure single sign-on (SSO), synchronized user ID authentication, and user-based identity services across key firewall services. SSO authentication lets administrators access the web admin console and lets users to access services such as the captive portal and remote access VPN tunnels.

Sophos Firewall can also retrieve Microsoft Entra ID group membership information and use it to apply user and group-based policies and administrator access profiles.

The integration uses OAuth 2.0 and OpenID Connect (OIDC) to deliver reliable identity management.

Where you can use Microsoft Entra ID

You can configure Microsoft Entra ID for the following services.

Web admin console

Firewall administrators can use SSO to access the web admin console. You can map their Microsoft Entra ID roles or groups to the firewall's device access profiles through the server configuration in the firewall, ensuring identity‑based permissions.

User services

All users, including administrators, can use SSO to access some services in the firewall. Policies and firewall rules apply access permissions for these services.

The services that support Microsoft Entra ID are as follows:

  • Captive portal: For users accessing web resources.
  • Remote access VPN: For users accessing internal resources through VPN tunnels.

    • VPN portal
    • SSL VPN through the Sophos Connect client
    • IPsec VPN through the Sophos Connect client

Note

Windows devices running Sophos Connect client 2.4 or later support Microsoft Entra ID.

Synchronized user ID authentication

Microsoft Entra ID integration supports synchronized user ID authentication and Security Heartbeat user identification. These features require Sophos Fusion (previously Sophos Central) integration, Security Heartbeat, and supported Sophos Endpoint software.

When Sophos Endpoint sends user identity information in heartbeat messages, the firewall uses the User Principal Name (UPN) to identify users and retrieve their Microsoft Entra ID group memberships.

This allows the firewall to apply user-based and group-based policies using current Microsoft Entra ID identity information.

Example UPN
john.doe@contoso.com

Configurations and troubleshooting

Note

Alternatively, you can use the Microsoft Entra ID Domain Services for authentication to services, such as the user portal and client authentication agent (CAA), in addition to the web admin console and captive portal. See Sophos Firewall: Integrate Sophos Firewall with Microsoft Entra ID.

Videos

Watch the following videos.

Entra ID SSO integration for the Sophos Connect client

Captive portal SSO and group import