Additional Information Regarding User Groups and Policy Control

Options
MarlonLopes
MarlonLopes Posts: 2 image  Freshman Member

Hi everyone!

First of all, thank you for the excellent guide. I would like to share an important detail that is not covered in the procedure and may help other administrators who intend to use Microsoft Entra ID to apply different policies through Policy Control.

After configuring the OIDC integration with Microsoft Entra ID, it is important to note that users must belong to Active Directory Domain Services (AD DS) groups that are synchronized with Entra ID and assigned to the Enterprise Application created for Captive Portal authentication.

The process that worked for me was:

  1. Create or identify the required user groups in AD DS.
  2. Ensure those groups are synchronized with Microsoft Entra ID.
  3. Assign the groups to the Enterprise Application created for the Captive Portal integration.
  4. Locate and copy the Object ID of the user group in Microsoft Entra ID.
  5. On the firewall, create one or more user groups as needed:
    • User Type: External Group User
    • Authentication Server: The OIDC Server created previously
    • Group Identifier: The Object ID of the corresponding group in Entra ID

Important: The value used in the Group Identifier field must be the Object ID of the user group (AD DS / Entra ID group). Do not use the Object ID of the Enterprise Application, as these are different identifiers and group membership mapping will not work correctly.

Once the groups have been created on the firewall, they can be referenced in Policy Control rules, allowing different security profiles to be applied based on the user's group membership.

Another important detail is that, for Content Filter and AppPatrol profiles to be applied successfully after Captive Portal authentication, the firewall rule should use oidc-users in the User field.

Without these additional configurations, users may authenticate successfully through Entra ID, but the firewall may not correctly identify their group membership, preventing group-based policies from being applied as intended.

I hope this information helps other community members during the implementation of OIDC authentication with Microsoft Entra ID.

Thank you again for the guide.

Best regards,

Marlon Benfica.

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 933 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @MarlonLopes,

    Thank you for sharing this with us. We will review the article again and see where improvements or adjustments are needed.

    (Feel free to create new posts with any additional feedback or sharing, as this can help you earn more coins and may also benefit other users with similar use cases.😉)

    Zyxel Tina

Nebula Tips & Tricks