Azure Firewall to secure LDAPS

Sadaqah Aid 20 Reputation points
2025-10-18T12:31:00.5333333+00:00

Hello,

I would like some assistance please.

I have Server 2022 configured with LDAPS and I would like to configure Azure Firewall to secure inbound LDAPS with FQDN / IP ranges.

I have Workspace ONE UEM and would like to integrate SAML / Entra ID but do not want LDAPS port 636 to be open, so I would like to configure Azure Firewall to secure inbound LDAPS with FQDN / IP ranges.

Can you please assist me and provide documentation.

Thanks

Sahid

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jeevan Shanigarapu 3,105 Reputation points Microsoft External Staff Moderator
    2025-10-20T04:29:23.1166667+00:00

    Hello @Sadaqah Aid,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand your question. You would like to secure inbound LDAPS (port 636) traffic using Azure Firewall and integrate Workspace ONE UEM with Entra ID.

    Here is the suggested approach:

    Protecting LDAPS using Azure Firewall: Azure Firewall allows filtering by FQDNs and IP addresses for outbound traffic only. For inbound LDAPS (port 636), filtering by FQDN is not supported; inbound rules can only be set using IP address ranges.

    Best Practices:

    Limit inbound LDAPS access to trusted IP ranges only.

    Do not expose LDAPS directly to the internet, use a VPN or ExpressRoute for secure connections.

    How to configure Firewall rule: Azure Firewall rule processing logic | Microsoft Learn

    Secure LDAP with Azure AD DS__:__ Tutorial - Configure LDAPS for Microsoft Entra Domain Services - Microsoft Entra ID | Microsoft Learn

    Integration of Workspace ONE UEM with Entra ID

    For SAML integration, LDAPS is mainly used for directory synchronization rather than authentication. To keep LDAPS secure and internal, you should:

    Run Azure AD Connect or Workspace ONE Directory Sync behind your firewall, and use Azure Firewall network rules to restrict LDAPS access to internal traffic only.

    Get started integrating Microsoft Entra ID with apps - Microsoft Entra ID | Microsoft Learn

    Kindly let us know if the above helps or you need further assistance on this issue.

    Please do not forget to "Accept the answer” and “up-vote it” wherever the information provided helps you, this can be beneficial to other community members__.__ It would be greatly appreciated and helpful to others.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.