How to Authenticate Microsoft 365 Users with a Sophos Firewall
Question details
The user needs to authenticate Microsoft 365 cloud identities through a Sophos Firewall, as direct LDAP synchronization is not typically supported for pure cloud identities.
- Product
- Microsoft 365 / Sophos Firewall
- Device & OS
- not provided
- Scenario
- Setting up user authentication and synchronization for a network secured by a Sophos Firewall using Microsoft 365 credentials.
- Observed behavior
- Traditional LDAP cannot directly synchronize Microsoft 365 cloud identities to the Sophos Firewall without additional configuration or alternative protocols.
Verify your specific Sophos Firewall firmware version and ensure you have administrative access to both your Sophos appliance and your Microsoft Entra ID (formerly Azure AD) portal.
Configure Authentication via Microsoft Entra ID (SAML/RADIUS)
Use modern authentication methods like SAML or RADIUS to integrate Microsoft 365 identities with your Sophos Firewall.
Because Microsoft 365 cloud identities cannot be synced directly via traditional LDAP, you must determine your environment type (Microsoft Entra ID, on-premises Active Directory Domain Services, or Microsoft Entra Domain Services).
Once identified, you can use SAML, RADIUS, or a supported synchronization tool which are broadly supported by modern Sophos appliances for cloud identity integration.
Check whether your organization uses pure Microsoft Entra ID, on-premises Active Directory, or Microsoft Entra Domain Services to determine the compatible authentication protocol.
Navigate to the official Sophos documentation specific to your firewall model to find integration guides for SAML, RADIUS, or Microsoft Entra ID.
Configure Microsoft Entra ID as the Identity Provider. Add the Sophos Firewall as an enterprise application in your Microsoft portal to enable SSO and pass authentication tokens.
In the Sophos firewall admin console, navigate to Authentication > Servers and add your Microsoft Entra ID or RADIUS server using the integration details generated from your Microsoft portal.
Looking for a Lightweight Alternative to Microsoft 365?
If managing complex Microsoft 365 cloud environments and network synchronizations becomes overwhelming, consider WPS Office. It provides a robust, easy-to-use desktop office suite that does not rely on complex cloud identity integrations for everyday document work.
- 1. Download and Install: Visit the official WPS website to download the free, lightweight installer.
- 2. Open Your Microsoft Documents: Launch WPS Office and seamlessly open your existing Word, Excel, or PowerPoint files without conversion.
- 3. Edit and Save: Make your changes and save the files in their native Microsoft formats to maintain perfect compatibility with other users.

Frequently Asked Questions
Why can't I use traditional LDAP for Microsoft 365 identities on my Sophos Firewall?
Microsoft 365 uses Microsoft Entra ID for cloud identities, which relies on modern authentication protocols like SAML or OAuth rather than traditional on-premises LDAP.
Does Sophos Firewall support Microsoft Entra ID (formerly Azure AD)?
Yes, modern Sophos Firewalls support Microsoft Entra ID integration. This is typically achieved by leveraging SAML authentication or connecting through Microsoft Entra Domain Services.
Where can I find the specific configuration steps for my Sophos model?
You should refer directly to the official Sophos documentation and support portal, as configuration steps and supported protocols vary significantly depending on your specific hardware model and firmware version.




