> Source: [sk144212](https://support.checkpoint.com/results/sk/sk144212)

# sk144212 - How to configure Office 365 and Centrify with CloudGuard SaaS Authentication Service

| Property | Value |
|----------|-------|
| Solution ID | sk144212 |
| Date Created | 2019-01-14 |
| Last Modified | 2019-04-25 |
| Technical Level | General |

## Solution

**Table of Contents:**

* Introduction
* Prerequisites
* Procedure
  * Add and Configure Centrify as an Identity Provider
  * Configure Office 365 to use CloudGuard SaaS Authentication Service as Identity Provider

Introduction {#Introduction}
----------------------------

This article will show you how to configure CloudGuard SaaS to work with Centrify as an Identity Provider and Microsoft Office 365. After you complete the configuration, all login requests to Office 365 will go through CloudGuard SaaS Authentication Service.

**Important Notes**

* This procedure will i**mpact all Office 365 users** in your domain; it cannot be done for specific user groups only.
* Changing the Identity Provider for Office 365 might **take up to 2 hours to propagate** to all Microsoft datacenters. Click [here](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-federation-saml-idp) for more information.
* Besides the configuration described in this article, you need to **associate Microsoft Office 365** to CloudGuard SaaS in order to **synchronize your users** . This is done under Identity Protection\\Configuration\\SaaS Applications. Please consult the [Identity Protection Admin Guide](https://sc1.checkpoint.com/documents/CloudGuard_SaaS_IdentityProtection/html_frameset.htm), section *Getting Started - Initial Configuration*, for more details.

Prerequisites {#Prerequisites}
------------------------------

1. Machine with **PowerShell** running on one of the following **64-bit versions of Windows**: Windows 10, Windows 8.1, Windows 8, Windows 7 Service Pack 1 (SP1), Windows Server 2016, Windows Server 2012 R2, Windows Server 2012, or Windows Server 2008 R2 SP1.
2. **Microsoft Azure Active Directory Module for Windows PowerShell** (the presence of the module will be verified automatically by the script run in step 10 of the Office 365 configuration. If the module is missing, the script will provide installation instructions.
3. **Administrator access** to Centrify and Office 365.

Procedure {#Steps}
------------------

### Add and configure Centrify as an Identity Provider {#Centrify}

1. Log into the Centrify Admin portal and create a new web application: under **Apps** , select **Web Apps** and click on**Add Web Apps**.
2. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify11901210457.png)
3. In the pop-up that opens, select the **Custom** tab and scroll down to **SAML** . Click on **Add** and then **Yes** in the confirmation window. Then click **Close**.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify21901210457.png)
5. Edit the **Name** (e.g., CloudGuard SaaS - Authentication Service), **Description** and **Category** (Security) of the SAML App you created above and click **Save**.
6. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify31901210613.png)
7. In the **Trust** section, under **Identity Provider Configuration**, download the metadata file. You will need to upload it later to the CloudGuard SaaS portal.
8. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify41901210614.png)
9. 
10. Log into the CloudGuard SaaS portal and go to **Configuration** under the module **Identity Protection** . Under the tab **Identity Providers** , click on **Add Identity Provider**.
11. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP1901210614.PNG)
12. In the wizard that opens, select **Centrify** and click **Next**.
13. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP_Centrify11901210614.PNG)
14. Enter your domain name and click **Next**.
15. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP_Centrify21901210615.PNG)
16. Copy the Entity ID and the Reply URL to a text file and save them for later. Click **Next**.
17. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP_Centrify31901210615.PNG)
18. Upload the metadata file you downloaded from the Centrify Admin Portal in Step 4. Click **Next**.
19. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP_Centrify41901210615.PNG)
20. Go to the Centrify Admin portal. In Web Apps, open your SAML Application. In the**Trust** section, under **Service Provider Configuration** , choose **Manual Configuration** . In the field**SP Entity ID/Issuer/Audience** , enter the Entity ID copied from the CloudGuard SaaS dashboard in step # 8. In the field **Assertion Consumer Service (ACS) URL** , enter the Reply URL copied from that same step # 8. Click **Save**.
21. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify51901210616.png)
22. Scroll down to the field Name ID Format and select **Persistent** . Click **Save**.
23. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify61901210616.PNG)
24. In the **Permissions** section, click **Add** and add the role configured for your Office 365 users. Click **Add** and then **Save**.
25. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify71901210616.png)
26. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify81901210617.PNG)
27. In the Centrify Admin Portal, navigate to the **SAML Response** section of the Web App you added for CGS Authentication Service. Click **Add**and enter the following values:
28. Attribute Name: **/claims/immutableid**
29. Attribute Value: **LoginUser.Base64EncodedGuid**
30. Click Save.
31. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify91901210447.png)
32. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Centrify101901210448.PNG)
33. **Sign out from the Centrify Admin Portal.** Then, in the CloudGuard SaaS portal, click on **Check Connectivity**. This will open a Centrify login form which you will be prompted to enter an email address and password. After validation, you should see a Login Success message.
34. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add IDP_Centrify51901210622.PNG)
35. Click **Finish**to save your Identity Provider configuration and then close the wizard.

### Configure Office 365 to use CloudGuard SaaS Authentication Service as an Identity Provider {#Office}

1. In the CloudGuard SaaS portal, navigate to **Configuration** under**Identity Protection** . In the box corresponding to the AD FS Identity Provider you just configured, click on **Click to add SaaS**.
2. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk144212/Add SaaS_Centrify11901140448.png)
3. In the wizard that opens, select **Office 365** and click **Next**.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add SaaS _ o3651901210622.png)
5. Entity ID and Reply URL are pre-filled. Click **Next**.
6. **Download Certificate** (do not edit the file name) and click **Finish** to save and close the wizard.
7. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk144212/Add SaaS_cert1901210623.png)
8. Download the script from [this link](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=72098). Extract the zip file to a folder. In that same folder, paste the certificate downloaded from the portal in the previous step.
9. Open Windows PowerShell, run it as an administrator, and navigate to the path of the extracted folder.
10. Execute the following command in order to bypass script execution policy for the current PowerShell session only:
11. `Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass`
12. Run the PowerShell script downloaded in step # 5.
13. `.\office365_auth_service_sso.ps1 -domain <domain_name> -entity <entity_id>`
14. You will be prompted to log into Office 365 with **global**administrator credentials.
15. \<entity_id\> is the Entity ID URL copied in Step # 8 of the **Add and Configure Centrify as an Identity Provider** section. You can also find it by clicking on **Edit**on your Identity Provider in the CloudGuard SaaS portal.
16. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk144212/Add SaaS_Centrify21901140452.png)
17. **After you execute this script, Office 365 will be configured to use CloudGuard SaaS Authentication Service as an Identity Provider for all users.**
18. You have now completed the configuration. All login requests to Office 365 will now go through CloudGuard SaaS Authentication Service. Login events will be shown in the CloudGuard SaaS portal under**Identity Protection\\Events**.

**Note**: Due to a limitation on the side of Centrify, when trying to login to Office 365, users will enter their email in the Office 365 login page and will need to re-enter it in the Centrify login screen.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
