<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: do we need domain admin rights for the service account in Identity awareness in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199924#M37503</link>
    <description>&lt;P&gt;Im fairly sure you do. Though below sk, if you can make it work, should suffice, but I was never able to get it going, even with TAC on the phone.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk93938" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk93938&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Dec 2023 02:05:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-12-07T02:05:39Z</dc:date>
    <item>
      <title>do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199922#M37501</link>
      <description>&lt;P&gt;do we need domain admin rights for the service account in Identity awareness&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 01:47:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199922#M37501</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-12-07T01:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199923#M37502</link>
      <description>&lt;P&gt;Please explore Identity Collector further as the preferred method.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1" target="_blank"&gt;Identity Collector - Requirements (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 02:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199923#M37502</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-07T02:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199924#M37503</link>
      <description>&lt;P&gt;Im fairly sure you do. Though below sk, if you can make it work, should suffice, but I was never able to get it going, even with TAC on the phone.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk93938" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk93938&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 02:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199924#M37503</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-07T02:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199969#M37507</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/83845"&gt;@tavi0906&lt;/a&gt;&amp;nbsp; you can use the&amp;nbsp;sk93938 mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using ad query in my enviroment and it's working properly.&lt;/P&gt;&lt;P&gt;You must configure the permissions for the service account in all ad servers, it's not necessary be a domain admin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 13:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199969#M37507</guid>
      <dc:creator>cassiomaciel</dc:creator>
      <dc:date>2023-12-07T13:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199980#M37509</link>
      <description>&lt;P&gt;If you got that sk going, then it sefinitely would work : - )&lt;/P&gt;
&lt;P&gt;I dont know, I was never able to succeed at it, even with TAC help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 14:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/199980#M37509</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-07T14:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201251#M37840</link>
      <description>&lt;P&gt;why do we need the domain admin rights for service account ? any reason&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 02:59:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201251#M37840</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-12-21T02:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201253#M37841</link>
      <description>&lt;P&gt;It is not if you use the Identity Collector, and you should, as per the documentation that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;shared:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Requirements for Integration with Active Directory

Windows Server must connect to the Active Directory (AD) domain controllers of the organization with DNS, LDAP, and DCOM.

The Identity Collector requires an Active Directory (AD) user that belongs to the default Event Log Readers group.


Note - An administrative role is not required for this user.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 06:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201253#M37841</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-12-21T06:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201274#M37845</link>
      <description>&lt;P&gt;According to the sk we shared, you do not need an account with admin right, but as I said, I tried this with few different clients (TAC was on the phone every time) and we could never get it working. Clearly, we missed something... : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 11:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201274#M37845</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-21T11:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: do we need domain admin rights for the service account in Identity awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201277#M37846</link>
      <description>&lt;P&gt;You are talking about LDAP AU or something different?&lt;BR /&gt;For LDAP AU admin permissions are not required.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 12:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/do-we-need-domain-admin-rights-for-the-service-account-in/m-p/201277#M37846</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-12-21T12:22:37Z</dc:date>
    </item>
  </channel>
</rss>

