<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WMI Permission denied - From this months Windows Update in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159871#M28115</link>
    <description>&lt;P&gt;Thank you very much for the installation&amp;amp;configuration steps. I also didn't want to use Identity Collector as it means two more agents, two more vms, two more things to maintain. But since Check Point recommends it and now this problem I have no choice&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 06:53:47 GMT</pubDate>
    <dc:creator>BG</dc:creator>
    <dc:date>2022-10-19T06:53:47Z</dc:date>
    <item>
      <title>WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159491#M27921</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a number or R81.10 gateways which are still using AD lookups and we have the workaround in place to permit this to still work as per:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176148" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176148&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The next Microsoft date relating to this is supposed to be March 2023, however with this months patches going in on the domain controllers we have noticed our firewalls receiving the error WMI permission Denied when attempting to authenticate against the servers. Rolling back the patches on the AD server has fixed the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else facing this and aside from moving to AD Collector is there a fix for it?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Move-from-Identity-Awareness-AD-Query-to-ID-Collector-now/m-p/141483" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Move-from-Identity-Awareness-AD-Query-to-ID-Collector-now/m-p/141483&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 22:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159491#M27921</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2022-10-13T22:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159606#M27982</link>
      <description>&lt;P&gt;Similar situation.&amp;nbsp; We have the proper Jumbo installed since June to address compatibility with DCOM hardening fully enabled and working fine until Windows AD controllers updated with October patches.&amp;nbsp; Not seeing the tell tale event 10036 messages in AD event viewer that would be associated with the DCOM hardening issue.&amp;nbsp; Rechecked WMI permissions and don't see any issues, just getting WMI Permission Denied on the gateways.&amp;nbsp; &amp;nbsp;Opened a TAC case and waiting for a response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159606#M27982</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2022-10-14T18:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159615#M27989</link>
      <description>&lt;P&gt;After applying this month's patches, did you check to see if the registry key specified in &lt;A href="https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c" target="_self"&gt;kb5004442&lt;/A&gt; is still set appropriately?&lt;BR /&gt;In any case, our official recommendation is to use Identity Collector (mentioned in the SK you linked).&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 20:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159615#M27989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T20:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159617#M27991</link>
      <description>&lt;P&gt;Identity Collector is the way to go.&amp;nbsp; &amp;nbsp;Just fixed one site with it, working on the rest.&amp;nbsp; &amp;nbsp;Unofficial from TAC, delete if not appropriate to post here and accept my apologies in advance:&amp;nbsp; TAC found a commonality with a few of us that called in about the same thing, a ported hotfix on top of r80.40 jumbo 158 (bug introduced in Jumbo 156 that caused VPN timeouts after 2 hours sk178891). This SK also affects r81 &amp;amp; r81.10.&amp;nbsp; Seems it is a combination problem with the hotfix &amp;amp; the Microsoft October patches.&amp;nbsp; &amp;nbsp; Interesting that this hotfix is now incorporated in Jumbo 180 so wondering if it could haunt those that are still using AD query when it comes time to install Jumbo 180.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 22:09:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159617#M27991</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2022-10-14T22:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159659#M28003</link>
      <description>&lt;P&gt;Yes, as per George_Casper, we have the registry changes and hardening done, my experience is identical to his. I am now experiencing this at two sites. I expect other people will come across this as the patch cycle works through.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 19:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159659#M28003</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2022-10-16T19:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159660#M28004</link>
      <description>&lt;P&gt;P.S.&amp;nbsp; The identity collector was a breeze to install/config. Wish I did it months ago.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 20:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159660#M28004</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2022-10-16T20:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159822#M28104</link>
      <description>&lt;P&gt;Same situation here. R80.40 gateways with jumbo 158(no other hotfixes are installed as mentioned before). After october updates connection to domain controllers are broken with the message "WMI permission error [ntstatus = 0x80041003]". Uninstalling the update solves the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 11:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159822#M28104</guid>
      <dc:creator>BG</dc:creator>
      <dc:date>2022-10-18T11:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159832#M28106</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176148&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;sk176148: Check Point response to CVE-2021-26414 - "Windows DCOM Server Security Feature Bypass"&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 12:33:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159832#M28106</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-18T12:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159837#M28109</link>
      <description>&lt;P&gt;Applied windows patch was not&amp;nbsp;KB5004442 so I believe the problem is not related described in sk176148. Applied patch was&amp;nbsp;KB5018411 which was released this month for windows server 2016. Also I don't see any events with ID&amp;nbsp;&lt;SPAN&gt;10036&amp;nbsp;or "&lt;EM&gt;bad credentials or firewall blocks DCOM traffic [ntstatus = 0xc0000022]"&amp;nbsp;&lt;/EM&gt;error message using adlog tool. BTW uninstalling patch&amp;nbsp;KB5018411 solves the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 12:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159837#M28109</guid>
      <dc:creator>BG</dc:creator>
      <dc:date>2022-10-18T12:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159839#M28110</link>
      <description>&lt;P&gt;Same here, no signs of trouble with DCOM hardening.&amp;nbsp; Though may be related to DCOM or anything for that matter, the symptoms don't match at all in any way shape or form to either Microsoft's or Checkpoint's DCOM Hardening guidance.&amp;nbsp; &amp;nbsp;Spent hours on the phone with TAC on Friday trying to troubleshoot it.&amp;nbsp; &amp;nbsp; I'm sure someone will figure it out and create a hotfix or something else, but in the mean time just install Identity Collector and your problem will be solved in 20 minutes and it works.&amp;nbsp; &amp;nbsp;While nice to have a dedicated VM, you can stand it up on most any VM in a pinch and then move it to a dedicated VM later.&amp;nbsp; &amp;nbsp;It's surprisingly simple and not sure why I had a mental block about doing it 6 months ago but should have.&amp;nbsp; &amp;nbsp;Below is an unofficial quick cheat sheet on the install steps.&amp;nbsp; Its a 33MB installer that only takes a minute to install and about 20 to configure.&amp;nbsp; You can do some fancy stuff in there later on, looks like there's integration with Cisco ICE, Aruba and some other stuff.&amp;nbsp; Will have fun sometime later with that but out of the box vanilla config is quick and easy to replace AD Query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the gateway object in smart console select Identity Awareness. Then select Identity Collector check box. Hit the green + arrow and add a host object with the IP of the machine that will have IDC installed on it. It will generate a shared secret, save this secret. Install policy.&lt;BR /&gt;&lt;BR /&gt;Install IDC from this sk,&amp;nbsp;sk134312. After it is installed click the * (blue star for new object). Create a Domain, name it whatever you want. The Identity Collector requires an AD user that belongs to the default Event Log Readers group. Add that user and click test, then after a success click okay.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Click the blue star * again. Active Directory &amp;gt; Fetch Automatically &amp;gt; Provide the DC IP. Click Fetch &amp;gt; OK.&lt;BR /&gt;&lt;BR /&gt;Next create a query pool (in the top left). Give the query pool a name and click the check box in the top left to select the Domain Controller.&lt;BR /&gt;&lt;BR /&gt;Next create a Gateway object. I would name it the same name in Smart Console. Put in the IP address of the gateway in Smart Console. Apply that saved shared secret, add the query pool. Click test then trust. Click OK.&lt;BR /&gt;&lt;BR /&gt;After you confirm it's all connected uncheck Active Directory Query on your Gateway object in Smart Console. Install policy.&lt;BR /&gt;&lt;BR /&gt;On the CLI on your gateway you can verify connectivity with this command.&lt;BR /&gt;&lt;BR /&gt;# pdp connections idc&lt;BR /&gt;&lt;BR /&gt;P.S.&amp;nbsp; If you have a domain controller that identity connector won't connect to and you can ping it and looks good otherwise, on the DC itself, check Windows Firewall &amp;amp; make sure to Allow a Program Through the Firewall "Remote Event Log Management" and Domain network is Checked On&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 13:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159839#M28110</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2022-10-18T13:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159871#M28115</link>
      <description>&lt;P&gt;Thank you very much for the installation&amp;amp;configuration steps. I also didn't want to use Identity Collector as it means two more agents, two more vms, two more things to maintain. But since Check Point recommends it and now this problem I have no choice&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 06:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/159871#M28115</guid>
      <dc:creator>BG</dc:creator>
      <dc:date>2022-10-19T06:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160003#M28158</link>
      <description>&lt;P&gt;The Identity collector Technical overview recommends a 16 Gb of RAM and 12 core machines, and a maximum of 35 DCs per collector. In additon, to achive resiliency the recommendation is to have two separate windows machines configured identically.&lt;/P&gt;&lt;P&gt;One of our clients has in the order of 200+ DC. This would mean around&amp;nbsp; 12 windows machines are needed to support this environment.&lt;/P&gt;&lt;P&gt;What has the real world experience been? what spec Windows machines are people using and how many DCs per collector have people configured? are people running the collector directly on DCs?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 23:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160003#M28158</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2022-10-19T23:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160069#M28172</link>
      <description>&lt;P&gt;I haven't heard of anyone running Identity Collector on their AD server, FWIW.&lt;/P&gt;
&lt;P&gt;R81.20 has some pretty significant changes "under the hood" that will improve scalability and resiliency.&lt;BR /&gt;If I understand correctly, it should reduce the number of needed Identity Collector instances.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 15:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160069#M28172</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-20T15:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160089#M28181</link>
      <description>&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Thanks for the reply but you dont really answer the question. What is the really world experience with the resouce requirements for the identity collector? and will we need 10 plus instances of the collector to support an environment of 200+ Domain controllers if resilency is required? An additonal question, what, if any, thought has Check Point put into managing the collector versions? is there any ability to maintain the installed versions of the collector?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 19:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160089#M28181</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2022-10-20T19:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160094#M28182</link>
      <description>&lt;P&gt;You're correct in your assumptions you'll need that many Identity Collector instances.&lt;BR /&gt;My understanding is that real world experience bears these limits out.&lt;/P&gt;
&lt;P&gt;To clarify my statements around R81.20, these two bullets from the upcoming release tell the tale:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Improved resiliency, scalability, and stability for PDPs and Identity Brokers. Additional threads handle authentication and authorization flows.&lt;/LI&gt;
&lt;LI&gt;During a PDP failure, a PEP Identity Awareness Gateway can recover its identity database from connected PDP Gateways.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This should translate into needing less Identity Collector instances.&lt;/P&gt;
&lt;P&gt;Not sure what you mean by "managing the collector versions."&lt;BR /&gt;We always have the latest one here and provide a change log for past versions:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134312&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134312&amp;amp;partition=Advanced&amp;amp;product=Identity&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Earlier versions can likely be obtained from the TAC if necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 22:51:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160094#M28182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-20T22:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160095#M28183</link>
      <description>&lt;P&gt;Once again, thanks for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;to expand on my question re managing collector versions, I mean that should we have 10 + servers out there running the Identity collector, when a new version is released, is there a centralised method by which we can update all 10 servers? I am not sure how often new versions are released, but looking at the version history table, it appears it is now on the 15th release.&lt;/P&gt;&lt;P&gt;at the bottom of sk108235&lt;SPAN&gt;, there is a link to sk178086 - "How to Upgrade Indentity Collector version", clicking on this link I get "Sorry, this solution is deleted and can only be viewed by Check Point employees", What is in this article that CP do not want us to know?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 23:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160095#M28183</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2022-10-20T23:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160131#M28199</link>
      <description>&lt;P&gt;A centralized method to upgrade the servers?&lt;BR /&gt;Not that I'm aware of, but maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;(or one of his team) can comment on that as well as the upgrade procedure, which may be different than what is documented in the deleted sk.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 16:11:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160131#M28199</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-21T16:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160446#M28278</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AFAIK in sk176148 it says:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;To apply the Microsoft hardening and continue using AD Query and Identity Logging, you must install a hotfix.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The hotfix is included in Jumbo Hotfix Accumulators for these &lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/" target="_blank" rel="noopener"&gt;supported versions&lt;/A&gt; of Security Gateways / Security Management / Multi-Domain Servers:&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R81.10&lt;/A&gt; starting from Take 55&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R81&lt;/A&gt; starting from Take 60&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.40&lt;/A&gt; starting from Take 158&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.30&lt;/A&gt; starting from Take 251&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.20/Default.htm" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.20&lt;/A&gt; starting from Take 208&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm moving all of my customers to IC, but on some accounts, where this can't be done right away, I applied the JHF and it solved the issue. This was on R81.10 and R80.40 GWs. And yes, if you are in doubt, if this is the time to star using IC the answer is definitely yes - 15min and you are set. However Can CP please clarify the statement regarding JHF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br J&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 11:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160446#M28278</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-10-26T11:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160463#M28280</link>
      <description>&lt;P&gt;We have been given this as a possible fix from Microsoft.&amp;nbsp; &amp;nbsp; We are just starting testing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;H1&gt;KB5020439&lt;/H1&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.microsoft.com/en-us/topic/october-18-2022-kb5020439-os-build-14393-5429-out-of-band-f9840376-4f36-45c3-8dd8-f366c4b884dd" target="_blank" rel="noopener"&gt;https://support.microsoft.com/en-us/topic/october-18-2022-kb5020439-os-build-14393-5429-out-of-band-f9840376-4f36-45c3-8dd8-f366c4b884dd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 13:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160463#M28280</guid>
      <dc:creator>David_Evans</dc:creator>
      <dc:date>2022-10-26T13:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Permission denied - From this months Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160671#M28365</link>
      <description>&lt;P&gt;Identity Collector is a great solution for Gaia firewalls, But what is the solution for the SMB Gaia embedded firewall? Identity collector is not supported. We tested it anyway, but remote access didn't work after we activated Identity collector on the gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 13:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WMI-Permission-denied-From-this-months-Windows-Update/m-p/160671#M28365</guid>
      <dc:creator>FTZ</dc:creator>
      <dc:date>2022-10-28T13:41:00Z</dc:date>
    </item>
  </channel>
</rss>

