<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Both AD Query and Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232292#M44832</link>
    <description>&lt;P&gt;Hi, all!&lt;/P&gt;&lt;P&gt;Does it is normal to get user/IP associations using both AD Query and Identity Collector&amp;nbsp;&lt;SPAN&gt;simultaneously, or better choice is to choose one?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2024 09:00:38 GMT</pubDate>
    <dc:creator>Padre__</dc:creator>
    <dc:date>2024-11-11T09:00:38Z</dc:date>
    <item>
      <title>Both AD Query and Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232292#M44832</link>
      <description>&lt;P&gt;Hi, all!&lt;/P&gt;&lt;P&gt;Does it is normal to get user/IP associations using both AD Query and Identity Collector&amp;nbsp;&lt;SPAN&gt;simultaneously, or better choice is to choose one?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 09:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232292#M44832</guid>
      <dc:creator>Padre__</dc:creator>
      <dc:date>2024-11-11T09:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Both AD Query and Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232327#M44840</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/119365"&gt;@Padre__&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short: Use Identity Collector. It is much more safe, an this is the preferred method.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In the October 2022 Windows update (&lt;A href="https://support.microsoft.com/en-us/topic/october-11-2022-kb5018411-os-build-14393-5427-a59be55a-b368-4284-a643-28fc0b9b8314" target="_blank" rel="noopener"&gt;KB5018411&lt;/A&gt;/&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/topic/october-11-2022-kb5018419-os-build-17763-3532-ca62cca7-b599-44c4-a2a6-347996662623" target="_blank" rel="noopener"&gt;KB5018419&lt;/A&gt;), Microsoft made changes to read privileges that affect AD Query from an Identity Awareness Gateway to a DC. If AD Query is configured for a DC user who is not an admin (see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93938" target="_blank" rel="noopener"&gt;sk93938&lt;/A&gt;), AD Query cannot access the DC. For customers with such a configuration, Check Point recommends to use Identity Collector as the Identity Source instead of AD Query. For more information and workaround procedures, see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk180232" target="_blank" rel="noopener"&gt;sk180232&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk60301" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk60301&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 14:04:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232327#M44840</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-11T14:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Both AD Query and Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232331#M44841</link>
      <description>&lt;P&gt;Identity Collector is preferred and is better performing than Adquery.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 14:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232331#M44841</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-11-11T14:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Both AD Query and Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232703#M44972</link>
      <description>&lt;P&gt;&lt;EM&gt;AD Query and Identity Collector conflict and should not be used as the identity connector for the same gateway. Events may arrive out of sync and the same event may be observed multiple times, leading to unpredictable results&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.checkpoint.com/downloads/products/cp-identity-awareness-reference-architecture-best-practices.pdf" target="_blank"&gt;https://www.checkpoint.com/downloads/products/cp-identity-awareness-reference-architecture-best-practices.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 10:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-AD-Query-and-Identity-Collector/m-p/232703#M44972</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-11-14T10:53:27Z</dc:date>
    </item>
  </channel>
</rss>

