Short answer
You need control of DNS for the domains being protected, plus proof of domain ownership. For Zero Trust, FirstNet needs your identity provider details and a catalogue of the applications in scope with their owners. For Magic Transit, FirstNet needs your public IP ranges and ASN.
In detail
The full checklist:
- DNS control and proof of ownership for each domain to be proxied
- Identity provider details: SAML or OIDC endpoint, attribute mapping and MFA set-up
- An application catalogue: apps, owners and current access methods
- Public IP ranges and ASN details for Magic Transit
- A named technical contact for service requests and approvals
- Agreed change windows and acceptance criteria before cutover
FirstNet then follows a staged delivery: discovery and design, account set-up with SSO, MFA, audit logging and role-based access, onboarding by product family, policy hardening and SIEM integration, cutover and handover, then ongoing managed tuning.
Details of existing WAF, VPN, CDN or MPLS investments also help FirstNet plan a phased migration. If your identity provider needs work first, FirstNet identifies the gaps early so they do not delay cutover.
Source: FirstNet Web Application & DDoS Protection service page →
Didn’t answer your question?
