cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Piyapon
Level 8
Report Inappropriate Content
Message 1 of 6

Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Customer organization will use WGCS and authenticate with Azure AD SAML. They don't have ADFS on prem. 

I tried to follow this step (https://community.mcafee.com/t5/Enterprise-Documents/Web-Gateway-Cloud-Service-Configuring-SAML-Auth...)

After completed all step, It redirects to log in page but after type e-mail address, it come back to log in page again. Anyone has ever faced this issue.

Thanks 

1 Solution

Accepted Solutions
Piyapon
Level 8
Report Inappropriate Content
Message 6 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Dear @Niks 

 

I have set it to port 8084. Just in case it might be cached in browser. I reproduce issue again and this time I have already clear browser cache and close browser before reproduce har file. Please see it might help you to investigate.

Proxy: http://c1198155036.saasprotection.com
port: 8084
Exception list: *lala-it.com;*microsoftonline.com;*msftauth.net;*msauth.net;*msauthimages.net;static-exp1.licdn.com
Test URL : Office.com

View solution in original post

5 Replies
Niks
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Hi @Piyapon ,

In the browser exceptions need to add the ADFS domain, this will allow the browser to communicate directly to the identity provider. If you are using Azure Active Directory you can use the below list in a browser exception

*microsoftonline.com
*msftauth.net
*msauth.net
*msauthimages.net
static-exp1.licdn.com

Suggest you use the developer tool to check if URL related to IDP are making a direct connection or redirecting to WGCS.

Regards,

Nikhil

Piyapon
Level 8
Report Inappropriate Content
Message 3 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Thank you Niks for fast response but It still doesn't work. It keeps getting pop up on authentication page. Any additional config I may missed

Piyapon
Level 8
Report Inappropriate Content
Message 4 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

@Niks  I cannot attach files in private message. I followed your instruction and generate 2 files here

Niks
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 5 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Hi @Piyapon ,

Which port are you using for in browser settings?  Browser settings should be configured redirect to port 8084 port.

https://community.mcafee.com/t5/Enterprise-Documents/Web-Gateway-Cloud-Service-Configuring-SAML-Auth...

From HAR file noticed browser is redirecting to port 80

Request URL: https://saml.saasprotection.com/mwg-internal/de5fs23hu73ds/plugin?target=Auth&reason=Auth&setCookie=...

Request Method: GET
Status Code: 403 LoginPageSaaS

Remote Address: 185.221.69.144:80

 

Regards,

Nikhil

Piyapon
Level 8
Report Inappropriate Content
Message 6 of 6

Re: Cannot Authen SAML with Azure AD with WGCS

Jump to solution

Dear @Niks 

 

I have set it to port 8084. Just in case it might be cached in browser. I reproduce issue again and this time I have already clear browser cache and close browser before reproduce har file. Please see it might help you to investigate.

Proxy: http://c1198155036.saasprotection.com
port: 8084
Exception list: *lala-it.com;*microsoftonline.com;*msftauth.net;*msauth.net;*msauthimages.net;static-exp1.licdn.com
Test URL : Office.com

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community