<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Authentication with AD based on groups</title><link>https://community.sophos.com/web-appliance/f/discussions/97427/authentication-with-ad-based-on-groups</link><description>I&amp;acute;d like to do authentication based on groups. My appliance is a WSA500. 
 I only want to allow internet access to users in the AD group ghttp. 
 Is that possible? 
 If yes, please tell me how. 
 Thanks, 
 Holger</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/385955?ContentTypeID=1</link><pubDate>Fri, 12 Oct 2018 12:11:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2f3127ee-adeb-4249-b121-fdb6468abdca</guid><dc:creator>Paul Nikelson</dc:creator><description>&lt;p&gt;Thank you!! I wanted to do the same something in my site:&amp;nbsp;&lt;a title="https://descargar-geometrydash.com/" href="https://descargar-geometrydash.com/"&gt;https://descargar-geometrydash.com/&lt;/a&gt;&amp;nbsp;and I could do it.&lt;/p&gt;
&lt;p&gt;Now, I will try to replicate to other sites I am managing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/354559?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 09:39:52 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f0152a08-fb40-4b09-9f90-a6f2c10a99e5</guid><dc:creator>Michael Dunn</dc:creator><description>&lt;p&gt;Go to the Policy Test menu item.&amp;nbsp; Enter in the destination and user name and test.&lt;/p&gt;
&lt;p&gt;If the &amp;quot;Policy&amp;quot; that it hits is Default Policy, then you have a problem with Default Groups.&lt;/p&gt;
&lt;p&gt;If the Policy is the name of one of your additional policies, you have a problem with that one, check the first tab.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/354479?ContentTypeID=1</link><pubDate>Sun, 05 Nov 2017 05:03:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cf4c420c-0b98-4f3d-92fa-afb6e77e27fa</guid><dc:creator>ChristianZittar</dc:creator><description>&lt;p&gt;Dear Michael,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;thanks for the informations.&lt;/p&gt;
&lt;p&gt;Under Default Groups I have selected the radio button, Only selectewd Entries&lt;/p&gt;
&lt;p&gt;Under System Authentication is Block Access&lt;/p&gt;
&lt;p&gt;Under Recent Activity Search I have the usernames.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/354392?ContentTypeID=1</link><pubDate>Fri, 03 Nov 2017 15:41:34 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:812e9a6e-b73d-4c01-b9e1-46028b143f83</guid><dc:creator>Michael Dunn</dc:creator><description>&lt;p&gt;Under Default Groups, make sure that your radio button is selected as you are trying to configure.&lt;/p&gt;
&lt;p&gt;Under System Authentication, authentication failure, make sure that you Block access.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If it is still allowing access that it shouldn&amp;#39;t, under the Recent Activity Search, is it showing the usernames or the IPs?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/353868?ContentTypeID=1</link><pubDate>Tue, 31 Oct 2017 03:51:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e6dee050-42cd-40f6-9314-34fdbe6b4532</guid><dc:creator>ChristianZittar</dc:creator><description>&lt;p&gt;Thanks Karlos,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I saw the points in the menus.&lt;/p&gt;
&lt;p&gt;But one question is coming up everytime:&lt;/p&gt;
&lt;p&gt;Why does everyone has access to the internet although I configured in the Group Policy default groups menu, that only specific groups are allowed to!?&lt;/p&gt;
&lt;p&gt;But I have users which are not member of this group ghttp which are still allowed to access the internet....&lt;/p&gt;
&lt;p&gt;Any thoughts?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Or is your suggestion to fix it with additional Policy my solution already?&lt;/p&gt;
&lt;p&gt;Thanks in advance,&lt;/p&gt;
&lt;p&gt;Holger&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Authentication with AD based on groups</title><link>https://community.sophos.com/thread/353824?ContentTypeID=1</link><pubDate>Mon, 30 Oct 2017 18:42:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:da493908-8ccf-4ab5-aa10-779ade246a79</guid><dc:creator>Karlos</dc:creator><description>&lt;p&gt;Hi Holger,&lt;/p&gt;
&lt;p&gt;There&amp;#39;s several ways to achieve this goal, here is one way:&lt;/p&gt;
&lt;p&gt;First, make sure you set up AD Authentication on your appliance:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;-&amp;nbsp;&lt;a href="/kb/en-us/126599" target="_blank"&gt;Sophos Web Appliance: requirements and best practices to setup authentication&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;-&amp;nbsp;&lt;a href="http://wsa.sophos.com/docs/wsa/webhelp/tasks/ConfigSysActiveDirectoryAccess.html" target="_blank"&gt;Configuring Active Directory Access&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Then you can set up your default policy to block all&lt;/p&gt;
&lt;p&gt;Lastly, you can set up an Additional Policy - specify AD group&amp;nbsp;ghttp and allow the categories you would like for them to be able to access&lt;/p&gt;
&lt;p&gt;Cheers,&lt;/p&gt;
&lt;p&gt;Karlos&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>