{"id":24857,"date":"2024-07-10T09:20:55","date_gmt":"2024-07-10T17:20:55","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/07\/10\/news-18587\/"},"modified":"2024-07-10T09:20:55","modified_gmt":"2024-07-10T17:20:55","slug":"news-18587","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/07\/10\/news-18587\/","title":{"rendered":"Sophos ZTNA now supports on-premise Microsoft AD"},"content":{"rendered":"<p><strong>Credit to Author: Chris McCormack| Date: Wed, 10 Jul 2024 15:16:31 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-956120\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1.png?w=300\" alt=\"Logos\" width=\"300\" height=\"124\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1.png 712w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1.png?resize=300,124 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>We are pleased to announce the availability of Sophos ZTNA 2.1, which brings support for on-premise Microsoft Active Directory for identity, zero downtime, seamless failover between cloud points-of-presence, and important security enhancements.<\/p>\n<p>This release offers a new identity provider solution in addition to the existing cloud-based Microsoft Entra ID and Okta solutions already supported by Sophos ZTNA. It enables organizations without cloud infrastructure or a cloud-based identity platform to easily adopt Sophos ZTNA by leveraging their in-house Microsoft AD system for authentication with support for MFA through captchas or email OTPs.<\/p>\n<p style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956121 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png\" alt=\"Authentication\" width=\"1662\" height=\"1372\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png 1662w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png?resize=300,248 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png?resize=768,634 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png?resize=1024,845 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2.png?resize=1536,1268 1536w\" sizes=\"auto, (max-width: 1662px) 100vw, 1662px\" \/><\/p>\n<p>In addition, cloud gateways running on virtual platforms (ESXi or Hyper-V) now support zero downtime and seamless failover between cloud points of presence. This capability will also be available for Sophos Firewall-integrated ZTNA Gateways with the release of v20 MR2, which is scheduled for later this month. This new capability allows for seamless transitions to the next closest regional gateway in the event of an outage in your preferred gateway region, ensuring uninterrupted ZTNA access during the outage.<\/p>\n<p>An additional update with security enhancements is also available as ZTNA 2.1.1. You will need to first update your gateways to 2.1 and then apply the 2.1.1 update after that.<\/p>\n<h2>How to get the updates<\/h2>\n<p>The gateway image updates are available from Sophos Central. There is no need to update your ZTNA agents.<\/p>\n<p>1. In Sophos Central, navigate to the Gateways page and notice an indication that an image update is available. This notification is only seen on gateways hosted on ESXi and Hyper-V platforms. For gateways hosted on Sophos Firewall, they will be updated when applying firmware update v20 MR2 (available later this month).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956122 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png\" alt=\"Gateways\" width=\"1907\" height=\"501\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png 1907w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png?resize=300,79 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png?resize=768,202 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png?resize=1024,269 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3.png?resize=1536,404 1536w\" sizes=\"auto, (max-width: 1907px) 100vw, 1907px\" \/><\/p>\n<p>2. You can either initiate the upgrade immediately or schedule the upgrade for later. The update may take up to 30 minutes.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956123 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4.png\" alt=\"Upgrade\" width=\"770\" height=\"697\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4.png 770w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4.png?resize=300,272 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4.png?resize=768,695 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/p>\n<p>3. After the upgrade is completed and the gateway is back to &#8220;Active,&#8221; verify on the gateway\u2019s diagnostics console that all the tests pass before initiating the next update to ZTNA 2.1.1.<\/p>\n<p>Version 2.1.1 includes important security and vulnerability fixes, and we highly recommend that customers begin the upgrade process immediately. Upgrading to version 2.1.1 should also take approximately 30 minutes for a single node. The time required will be proportional if the deployment involves a multi-node cluster.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956124 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image5.png\" alt=\"Update\" width=\"765\" height=\"697\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image5.png 765w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image5.png?resize=300,273 300w\" sizes=\"auto, (max-width: 765px) 100vw, 765px\" \/><\/p>\n<p>4. Check the gateway console diagnostics once the update is complete and the gateway returns to the &#8220;Active&#8221; state. If all diagnostics checks pass, resource access can be resumed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956125 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png\" alt=\"Diagnostics\" width=\"1664\" height=\"471\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png 1664w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png?resize=300,85 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png?resize=768,217 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png?resize=1024,290 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image6.png?resize=1536,435 1536w\" sizes=\"auto, (max-width: 1664px) 100vw, 1664px\" \/><\/p>\n<h2>Documentation<\/h2>\n<p>The latest online documentation is <a href=\"https:\/\/docs.sophos.com\/central\/ZTNA\/startup\/en-us\/setup\/IdentityProvider\/index.html#__tabbed_1_1\">here<\/a>.<\/p>\n<p>The <a href=\"https:\/\/docs.sophos.com\/central\/ZTNA\/startup\/en-us\/troubleshooting\/index.html\">troubleshooting guide<\/a> has also been updated in case you encounter any issues during configuration.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2024\/07\/10\/sophos-ztna-now-supports-on-premise-microsoft-ad\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/09\/sophos-ztna.png\"\/><\/p>\n<p><strong>Credit to Author: Chris McCormack| Date: Wed, 10 Jul 2024 15:16:31 +0000<\/strong><\/p>\n<p>The gateway image updates are available from Sophos Central. There is no need to update your ZTNA agents.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[12235,24562,24564],"class_list":["post-24857","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-firewall","tag-products-services","tag-ztna"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24857"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24857\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24857"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}