01-22-2024 03:53 PM
Hi Team, my customer wants to deploy Umbrella in Azure and connect to their Azure AD without deploying VAs. Is this possible?
Reading the documentation, its seems its not possible to use the connector into Azure AD without VAs? Is this true? https://docs.umbrella.com/deployment-umbrella/docs/connect-active-directory-to-umbrella-1
Customer is quite averse to deploying and maintaining any appliances (i.e the VAs) and want strictly SaaS solution.
Solved! Go to Solution.
01-22-2024 04:27 PM - edited 01-22-2024 04:33 PM
Hi Madura,
You can integrate with Azure AD directly for the provisioning of users and Groups. User and group identities from Azure AD integrate with Umbrella DNS-layer security and Umbrella Secure Web Gateway (SWG) deployments. You do not need to deploy an on-premises Umbrella Active Directory Connector.
Umbrella DNS
Umbrella SWG
Note: Azure AD does not store the private IP to AD user mappings.
So without VA, for unmanaged endpoints ( without agents ), you will not get visibility of internal IP Address.
Reference: https://docs.umbrella.com/umbrella-user-guide/docs/microsoft-azure-ad-integration
01-22-2024 04:27 PM - edited 01-22-2024 04:33 PM
Hi Madura,
You can integrate with Azure AD directly for the provisioning of users and Groups. User and group identities from Azure AD integrate with Umbrella DNS-layer security and Umbrella Secure Web Gateway (SWG) deployments. You do not need to deploy an on-premises Umbrella Active Directory Connector.
Umbrella DNS
Umbrella SWG
Note: Azure AD does not store the private IP to AD user mappings.
So without VA, for unmanaged endpoints ( without agents ), you will not get visibility of internal IP Address.
Reference: https://docs.umbrella.com/umbrella-user-guide/docs/microsoft-azure-ad-integration
01-23-2024 09:02 AM
Just to add more context.
Above scenario is applicable where you have endpoints with Secure Client ( Anyconnect ) Umbrella Roaming module. In your scenario, where you dont have VA or do not want to have VA then Secure Client can provide Identity support for the end points on/off the network.
https://docs.umbrella.com/deployment-umbrella/docs/identity-support-for-the-roaming-client
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide