<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness using Azure AD in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205528#M38790</link>
    <description>&lt;P&gt;You can create local groups of the form EXT_ID_xxx (where xxx is the name of the group (with same capitalization as) in Azure AD.&lt;BR /&gt;See: &lt;A href="https://support.checkpoint.com/results/sk/sk177267" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177267&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 23:08:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-02-08T23:08:59Z</dc:date>
    <item>
      <title>Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/204623#M38588</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have tried configuring Azure AD as an Identity provider for Identity Awareness Access rules.&lt;/P&gt;&lt;P&gt;The Identity Provider object Azure is looking good.&lt;/P&gt;&lt;P&gt;The Azure AD object gives a green "connected" label when clicking "test connection".&lt;/P&gt;&lt;P&gt;All looking good. Until...&lt;/P&gt;&lt;P&gt;When I try to create a new access role and I browse Azure AD for users, the smartconsole throws an error saying "Failed to fetch objects from the Data Center. Please try again soon. If the issue persists, contact Check Point Support".&lt;/P&gt;&lt;P&gt;If I go to the drop down menu and select our on-prem AD it works as intended.&lt;/P&gt;&lt;P&gt;Now if I jump back and forth between the two, a couple of times, suddenly Azure AD works, and I am able to see my groups and users in Azure AD.&lt;/P&gt;&lt;P&gt;I can see the errors and successes in the cpm.elg log, but googling the errors gives me nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it is able to browse Azure AD i get this info message in the cpm.elg log:&lt;/P&gt;&lt;P&gt;INFO cloud.connection.GetAllCloudElementsCodeQueryHandler [xxxxxxxxxxxxxx-xxxxxxx]: finished processing.. number of results: 100, totalCount=4314&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it failes I get this error message in the cpm.elg log:&lt;/P&gt;&lt;P&gt;ERROR cloud.connection.GetAllCloudElementsCodeQueryHandler [xxxxxxxxxxxxxxxx-xxxxxxxx]: failed to execute command. error= at com.checkpoint.management.cloud.connection.GetAllCloudElementsCodeQueryHandler.performRemoteQUery(GetAllCloudElementsCodeQueryHandler.java:48)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the only issue was a buggy browsing experience, I wouldn't be too bothered, but none of my security policies created using Azure AD groups are working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I go about troubleshooting this issue? Are there other log files which may give me some more insight?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 08:18:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/204623#M38588</guid>
      <dc:creator>RobinJohnsen89</dc:creator>
      <dc:date>2024-01-31T08:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205528#M38790</link>
      <description>&lt;P&gt;You can create local groups of the form EXT_ID_xxx (where xxx is the name of the group (with same capitalization as) in Azure AD.&lt;BR /&gt;See: &lt;A href="https://support.checkpoint.com/results/sk/sk177267" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177267&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:08:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205528#M38790</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-08T23:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205529#M38791</link>
      <description>&lt;P&gt;I will look for great document someone on community sent me couple of years ago and if I find it, will attach.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205529#M38791</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T23:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness using Azure AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205534#M38792</link>
      <description>&lt;P&gt;K, got the doc, attached. Hope it helps.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-using-Azure-AD/m-p/205534#M38792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T23:20:15Z</dc:date>
    </item>
  </channel>
</rss>

