Hi Everyone,

We are currently managing all our Sophos Access Points via Sophos Central and were wondering whether it is possible to enable Single Sign-On (SSO) using Azure Active Directory for user authentication on the wireless network.

Could you please advise if such an integration is supported, and if so, whether there is any documentation or guidance available on how to implement it?

Many thanks in advance for your assistance.

6 Spice ups

There is no built-in system to handle this. But you could leverage 3rd party services specifically meant for this purpose. Some options I came across:

Get Started: RADIUS - JumpCloud

SecureW2 | Complete Platform for Passwordless Security

Foxpass: Cloud Radius Server & Cloud LDAP Server Authentication

Simplified Cloud RADIUS Server from Portnox - Portnox

4 Spice ups

Hi

Please use Network Policy Server (NPS) RADIUS service for SSO.

3 Spice ups

We use Sophos APs, best method is to use Microsoft NPS Radius and use Computer and Certificate Authentication. While SSO may seem more secure it does gives users the potential to logon to your corporate network via other devices using those credentials.

Yes, this can be futher secured by InTune but really the combination of the above and also Sophos Central Endpoint protection / restrict SSID to Sophos managed devices heartbeats should more than suffice.

Saying this if you aren’t managing your Sophos Endpoints via Sophos Central then its advised and very easy to move them away from Firewall managed and can be done with next to no downtime other than reboots to each AP.

Its also well worth hitting up your account manager as Sophos have always been to provide a free engineer call to scope out or answer questions regarding anything like this.