browsw Posted August 22, 2023 Posted August 22, 2023 We are just started exploring AzureAD joined devices and have most things working except Sophos filtering. Sophos support haven't been much help and I appreciate it is not officially supported yet (seems a bit slow of Sophos to me...) Staff can login on the AzureAD joined device and get identified correctly and get the correct firewall and staff filtering (I guess because we still have local AD and AzureAD Connect) However after 10 minutes of inactivity the user is logged out of the XGS firewall and receives the default filtering. I guess this is becuase STAS cannot WMI poll the workstation to check the user as it is AzureAD joined. This is verified by using the STAS WMI diagnostic and we get Access Denied. Has anyone had any luck getting AzureAD joined devices to work correctly with Sophos XGS? Maybe @Wave9_Lee might have some ideas? TIA!
HereIGoAgain2601 Posted August 22, 2023 Posted August 22, 2023 Have you got the Sophos Central Av suite - we moved from Stas to heartbeat authentication and haven’t looked back. It works great for intune and AD managed devices. Your Xg still needs to be joined to the DC to get the right membership though but it’s working for us as a holding solution until native Azure support is available in the XG. 1
Wave9_Lee Posted August 23, 2023 Posted August 23, 2023 We are just started exploring AzureAD joined devices and have most things working except Sophos filtering. Sophos support haven't been much help and I appreciate it is not officially supported yet (seems a bit slow of Sophos to me...) Staff can login on the AzureAD joined device and get identified correctly and get the correct firewall and staff filtering (I guess because we still have local AD and AzureAD Connect) However after 10 minutes of inactivity the user is logged out of the XGS firewall and receives the default filtering. I guess this is becuase STAS cannot WMI poll the workstation to check the user as it is AzureAD joined. This is verified by using the STAS WMI diagnostic and we get Access Denied. Has anyone had any luck getting AzureAD joined devices to work correctly with Sophos XGS? Maybe @Wave9_Lee might have some ideas? TIA! Hi - couple of things, could you see if you've WMI allowed on the client firewall rules? Some clues here https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/125318/sophos-firewall-best-practice-for-stas#mcetoc_1esth6tqs1m Also in SFOS20 released this quarter, native AZure Auth coming but as HereIGoAgain2601 says, integration with CIXA is the best way to go if you go serverless, great endpoint AV, synchronised security, single pane of glass etc - in light of this we have a great offer for cixa to make this move affordable.. See how you go with the WMI, drop me a note if you have any more issues, we have this working in lots of places. cheers 1
browsw Posted August 23, 2023 Author Posted August 23, 2023 Thank you both for your replies. I’ve disabled STAS and going to see how Heartbeat goes. Fingers crossed OS 20 will not be too long…
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now