<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory Objects in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243454#M47301</link>
    <description>&lt;P&gt;Could I create an object in policy that understands if a host (say a VM) is part of a particular AD group?&lt;/P&gt;&lt;P&gt;For example, if I wanted a policy that says Allow "UserVMs" to "[IntranetSites]" on "https".&lt;/P&gt;&lt;P&gt;Is it possible to have UserVMs as an object that is populated from a connection to AD?&lt;/P&gt;&lt;P&gt;Hope it's explained well enough... essentially trying to make policy a little more dynamic by using AD data.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2025 16:41:05 GMT</pubDate>
    <dc:creator>Anthony_Kahwati</dc:creator>
    <dc:date>2025-03-10T16:41:05Z</dc:date>
    <item>
      <title>Active Directory Objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243454#M47301</link>
      <description>&lt;P&gt;Could I create an object in policy that understands if a host (say a VM) is part of a particular AD group?&lt;/P&gt;&lt;P&gt;For example, if I wanted a policy that says Allow "UserVMs" to "[IntranetSites]" on "https".&lt;/P&gt;&lt;P&gt;Is it possible to have UserVMs as an object that is populated from a connection to AD?&lt;/P&gt;&lt;P&gt;Hope it's explained well enough... essentially trying to make policy a little more dynamic by using AD data.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 16:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243454#M47301</guid>
      <dc:creator>Anthony_Kahwati</dc:creator>
      <dc:date>2025-03-10T16:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243463#M47305</link>
      <description>&lt;P&gt;Yes, look at Access Roles &amp;amp; Identity Awareness.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Creating-Access-Roles.htm?tocpath=Configuring%20Identity%20Awareness%7C_____2#Creating_Access_Roles" target="_self"&gt;R81.20 Identity Awareness Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 19:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243463#M47305</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-10T19:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243464#M47306</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6010"&gt;@Anthony_Kahwati&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;yes, that‘s possible.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can get a Connection to AD via AccountUnit. And with Access-roles you can use AD objects like users, groups, machines in your rules. Additional you can connect via the datacenter object to your vitualization platform (VMware, AWS, Azure etc.) and use the objects from these platforms.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 19:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Directory-Objects/m-p/243464#M47306</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-03-10T19:58:39Z</dc:date>
    </item>
  </channel>
</rss>

