Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Integrate Active Directory with Sophos Firewall

Sophos
08/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


with Sophos Firewall. Let's dive in. In this TechVid, I'll show you how to add an Active Directory or AD server for authentication, import AD groups, and finally how to set AD as the primary authentication method. Before starting, make sure you're using a supported version of Sophos Firewall. This TechVid is demonstrated in SFOS version 21, so the steps and user interface shown may differ slightly in later versions. Next, make sure you have administrator rights to access your AD. You also need a domain user with rights to read AD group membership. Let's get started. First, add the AD server. In this TechVid, I'll be using the domain nointerface.ca. In Sophos Firewall, navigate to authentication. Make sure you're in the servers tab, then click AD. This opens the AD external server page, providing the configuration options for the server. In the server type, select Active Directory, then specify the server name. In this case, I'll name it Active Directory, and the server IP or domain is 10.2.0.100. In connection security, there are three options. Plain text, SSL TLS, or Start TLS. For SSL TLS or Start TLS, you need to install the Active Directory Certificate Services, or ADCS, role. In my case, I'll use SSL TLS. For steps on issuing a certificate in your domain controller using Active Directory Certificate Services, refer to the link in the video description. Next, to find the NetBIOS domain on your computer, go to Active Directory Users and Computers. Right-click the domain name and select Properties. Under Domain Name, you see the NetBIOS name, no interface. Copy this and paste it into the server configuration page. Next, add the server attributes for ADS username, password, and domain name. And lastly, enter the search query by clicking Add. In this case, the search query is OU equals VPN underscore users comma DC equals no interface comma DC equals CA. Note, when entering a search query, make sure there are no spaces and use commas in place of periods in the domain name. Click Add. Now, click Test Connection to validate the credentials. And you can see a notification that the test was successful. Click Save to finish the server configuration. The next step is to import AD groups. Click the Import icon to launch the Import Group Wizard, which guides you through the process in a few steps. Click Start to begin. In Step 1, go to the Base DN Search Queries drop-down menu and select the search query that was just created. Click the Next arrow to proceed. In Step 2, select the AD groups to import. Then, click Next. Here, you can select Common Policies for Groups. Once you've made your selections, click Next. In this case, Step 4 isn't necessary, so the Wizard tool skips directly to Step 5, showing a summary of the selections for review. Everything looks fine, so click Next followed by OK to migrate the groups to the device. Back in Sophos Firewall, go to the Groups tab to verify the recently imported AD groups. You're now ready to set Active Directory as a primary authentication method. Go to the Services tab. In the Authentication Server list, select Active Directory and move it to the first position in Selected Authentication Server. For the default group setting, choose the group to place users who are not explicitly assigned to any local group. By default, the default group is set to Open Group. Note, to create a profile on Sophos Firewall, the user must authenticate using one of the available methods. If the user doesn't belong to a local group, they'll be automatically added to the default group. Now, click Apply followed by OK to set the authentication method. The authentication method is now applied and the Active Directory Authentication Server has been added to the services on the page. For steps on issuing a certificate in your domain controller using Active Directory Certificate Services, refer to the link in the video description. That completes the steps to integrate Active Directory with Sophos Firewall. I hope you found this useful. The relevant documentation and other comprehensive resources for this tech vid are linked in the video description. Join the Sophos community to stay up to date with our products, ask questions, and get answers from Sophos experts. And go to Sophos TechVids for more expert tutorials to help you maximize your products and stay secure. See you next time.

TL;DR

  • Integrating Active Directory with Sophos Firewall requires adding an AD server, importing AD groups, and setting AD as the primary authentication method in the Services tab.
  • SSL/TLS connection security is recommended for AD integration but requires the Active Directory Certificate Services role to be installed on the domain controller first.
  • When entering LDAP search queries, use commas instead of periods in the domain name and ensure there are no spaces to avoid configuration errors.

Summary

This tutorial walks Sophos Firewall administrators through the complete process of integrating Active Directory (AD) with Sophos Firewall OS version 21. The video covers three core tasks: adding an AD server for authentication, importing AD groups into the firewall, and setting Active Directory as the primary authentication method. Before beginning, administrators need a supported SFOS version, administrator rights to the AD environment, and a domain user account with permissions to read AD group membership. During server configuration, the tutorial demonstrates selecting a connection security type — Plain Text, SSL/TLS, or Start TLS — with SSL/TLS recommended, which requires the Active Directory Certificate Services (ADCS) role to be installed on the domain controller. Key configuration details include specifying the server IP, NetBIOS domain name, ADS credentials, and a correctly formatted LDAP search query using commas in place of periods and no spaces. After validating the connection with a test, the Import Group Wizard guides administrators through selecting and migrating AD groups to the firewall. Finally, Active Directory is moved to the top of the Selected Authentication Server list in the Services tab, and a default group is assigned for users not explicitly mapped to a local group. The tutorial provides a practical, end-to-end walkthrough suitable for network administrators deploying identity-based policy enforcement on Sophos Firewall.

Chapters

0:00 - Introduction
0:10 - Overview & Prerequisites
0:45 - Add AD Server
2:32 - Import AD Groups
3:22 - Set Primary Auth Method

Key Quotes

1:18 "In connection security, there are three options. Plain text, SSL TLS, or Start TLS. For SSL TLS or Start TLS, you need to install the Active Directory Certificate Services, or ADCS, role."
2:13 "Note, when entering a search query, make sure there are no spaces and use commas in place of periods in the domain name."
3:46 "Note, to create a profile on Sophos Firewall, the user must authenticate using one of the available methods. If the user doesn't belong to a local group, they'll be automatically added to the default group."

FAQ

What connection security options are available when adding an Active Directory server in Sophos Firewall?

Sophos Firewall supports three connection security options: Plain Text, SSL/TLS, and Start TLS. For SSL/TLS or Start TLS, the Active Directory Certificate Services (ADCS) role must be installed on the domain controller. The tutorial demonstrates SSL/TLS as the chosen option.

What happens to users who authenticate via Active Directory but aren't assigned to a local group?

Users who authenticate but don't belong to a local group are automatically added to the default group, which is set to Open Group by default. Administrators can change this default group assignment in the Services tab during authentication method configuration.


Categories:
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • Identity & Access
  • How-To
  • Getting Started
  • Demo
  • Active Directory Integration
  • Firewall Authentication
  • LDAP Configuration
  • SSL
  • TLS Security
  • User Group Management
  • Identity-Based Policy
  • Sophos Firewall OS
  • Network Access Control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Integrate Active Directory with Sophos Firewall

              Industry Events (Sponsor Hosted)

              • Aug
                06

                Safeguarding Sensitive Data in the Age of AI Platforms

                08/06/202604:00 AM ET
                • Aug
                  06

                  AI Agents Transforming Identity Attack Tactics and Speed

                  08/06/202602:00 PM ET
                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Age of AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-age-of-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Transforming Identity Attack Tactics and Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-transforming-identity-attack-tactics-and-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version