I am looking at entra ID authentication related knowledge

<[email protected]> Fri, 29 May 2026 00:26:39 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============7985859248301406486==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_00BB_01DCEF01.D1965B90"
Content-Language: he

This is a multipart message in MIME format.

------=_NextPart_000_00BB_01DCEF01.D1965B90
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit

Hey,

 

I got a request to try and open access to a specific src ip address based on
a login to entra id using also 2fa.

There is a firewall in place which allows traffic based a src address list.

In order for the client ip to use the proxy for about 10-30 minutes he needs
to first access a login page which will in turn 
after the login will send the client IP address to a script/webhook which
will insert the client ip into the access list.

 

The employees has a static ip address from a dsl/fiber/lte provider.

I can be used with a session external_acl related helper.

 

It's not 100% squid related but I have never seen entra ID related topic
here in the list and it's weird to me so I'm popping it.

 

There are other options and combinations to do that but yet.. proxy
solutions with entra ID and 2fa seems pretty reasonable to me.

 

I do not have entra ID account or the ability to create one for now but if
there are others who might know a thing or two about entra ID
I will be glad to get some help.

 

Thanks,

Eliezer


------=_NextPart_000_00BB_01DCEF01.D1965B90
Content-Type: text/html;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 15 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	text-align:right;
	direction:rtl;
	unicode-bidi:embed;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;
	mso-ligatures:standardcontextual;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:11.0pt;}
.MsoPapDefault
	{mso-style-type:export-only;
	text-align:right;
	direction:rtl;
	unicode-bidi:embed;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US =
link=3D"#0563C1" vlink=3D"#954F72" style=3D'word-wrap:break-word'><div =
class=3DWordSection1><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>Hey,<o:p></o:p=
></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>I got a =
request to try and open access to a specific src ip address based on a =
login to entra id using also 2fa.<o:p></o:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>There is a =
firewall in place which allows traffic based a src address =
list.<o:p></o:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>In order for =
the client ip to use the proxy for about 10-30 minutes he needs to first =
access a login page which will in turn <br>after the login will send the =
client IP address to a script/webhook which will insert the client ip =
into the access list.<o:p></o:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>The employees =
has a static ip address from a dsl/fiber/lte provider.<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>I can be used =
with a session external_acl related helper.<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>It's not 100% =
squid related but I have never seen entra ID related topic here in the =
list and it's weird to me so I'm popping it.<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>There are =
other options and combinations to do that but yet.. proxy solutions with =
entra ID and 2fa seems pretty reasonable to me.<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>I do not have =
entra ID account or the ability to create one for now but if there are =
others who might know a thing or two about entra ID<br>I will be glad to =
get some help.<o:p></o:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'><o:p>&nbsp;</o=
:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>Thanks,<o:p></=
o:p></p><p class=3DMsoNormal =
style=3D'text-align:left;direction:ltr;unicode-bidi:embed'>Eliezer<o:p></=
o:p></p></div></body></html>
------=_NextPart_000_00BB_01DCEF01.D1965B90--


--===============7985859248301406486==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============7985859248301406486==--