Hello,
I decided to sync my Sophos with AD. The reasons are two: VPN Group-Sync from AD, and Webfiltering that should be user-based.
Reading the manual, reading forums, I decided to set it up.
Basically, Sophos seems to sync with AD. I tried prefetching, and that created users on the Sophos (but that is not what I want - now I have a bunch of local users). What I really want is Sophos "reading" the Group Membership in the AD, and then deciding if it's OK to access...
So what I basically did:
I created a dynamic membership group for VPN Users on the Sophos, and limited it to the single AD-Group, which contains users that should have SSL VPN access.
While I can confirm that if I prefetch the user, he is able to connect to the VPN with his windows password, but if I delete the user on the Sophos, and leave the group only, VPN connection fails.
For other settings, I have (in Authentication Services -> Advanced) AD Group Membership background sync enabled. I also synchronized manually. Prefetch is now empty, as I don't want it creating any users. And of course, this group on the Sophos (which is now synced with the AD group) is the one that is now in the VPN profile.
Reading this post, I'm thinking it must be possible:
I also checked the logs for VPN and authentication services:
VPN:
Thank you
This thread was automatically locked due to age.