<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Integration with Checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186084#M68009</link>
    <description>&lt;P&gt;For AD Query integration, you MUST use the Domain Admin account.&lt;BR /&gt;For Identity Collector, the account used must have the ability to read Security Event Logs.&amp;nbsp;&lt;BR /&gt;For LDAP group lookups (regardless of method), only an account that is able to read the directory is required.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 22:44:51 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-07-10T22:44:51Z</dc:date>
    <item>
      <title>AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186051#M68007</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;&lt;BR /&gt;One question, for the integration of the AD with the Checkpoint Firewall, is it necessary to use the "domain admin" account ???? Or how many privileges must have the server account, to be able to integrate the AD with Checkpoint? My customer does not want to "provide" the main domain admin accounts. &lt;BR /&gt;&lt;BR /&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 16:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186051#M68007</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-10T16:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186063#M68008</link>
      <description>&lt;P&gt;Short answer, it‘s not necessary to use a domain admin account.&lt;/P&gt;
&lt;P&gt;For Identity Collector you need a user with memberships the „&lt;SPAN class="Menu_Options"&gt;Event Log Readers&lt;/SPAN&gt;&lt;SPAN&gt; group“&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To browse the Active Directory, getting identities and reading groupmemberships you need a user with read rights in all OUs you want to read.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 18:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186063#M68008</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-10T18:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186084#M68009</link>
      <description>&lt;P&gt;For AD Query integration, you MUST use the Domain Admin account.&lt;BR /&gt;For Identity Collector, the account used must have the ability to read Security Event Logs.&amp;nbsp;&lt;BR /&gt;For LDAP group lookups (regardless of method), only an account that is able to read the directory is required.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 22:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186084#M68009</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-10T22:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186091#M68010</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;for AD query ther's no need to use an domain admin account&amp;nbsp;&lt;A title="Using Identity Awareness AD Query without Active Directory Administrator privileges on Windows Server 2008 and higher" href="https://support.checkpoint.com/results/sk/sk93938" target="_blank" rel="noopener"&gt;Using Identity Awareness AD Query without Active Directory Administrator privileges on Windows Server 2008 and higher&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of the new security features in newer windows releases AD query should not be used and it's not working without lowering the security on the windows server.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 05:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186091#M68010</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-11T05:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186100#M68011</link>
      <description>&lt;P&gt;I thought the recent changes Microsoft made broke all this?&lt;BR /&gt;Still, I agree: use Identity Collector.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 06:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186100#M68011</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-11T06:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186101#M68012</link>
      <description>&lt;P&gt;from&amp;nbsp;&lt;A title="AD Query cannot access DC server when AD Query is configured for non-admin user" href="https://support.checkpoint.com/results/sk/sk180232" target="_self"&gt;AD Query cannot access DC server when AD Query is configured for non-admin user&lt;/A&gt;&amp;nbsp;workaround 2 states using a member of domain admin group. But does not work with the newest windows releases.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;forget about AD query. Identity Collector, Identity Agent, MUH agent are the working solutions.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 06:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186101#M68012</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-11T06:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186154#M68013</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;One doubt, for the Identity Collector, is it mandatory that the AD account used belongs to the group "Event Log Readers"?&lt;/P&gt;
&lt;P&gt;It is not possible to work this integration with an "any" user of the AD, which is in "read only" mode?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 23:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186154#M68013</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-11T23:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186157#M68014</link>
      <description>&lt;P&gt;I tried that sk with 4 different customers in the past, every time even TAC was on the phone, and we got it working once for like 1 day and then broke and could not be fixed again, so we just gave up on it.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 00:14:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186157#M68014</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-12T00:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186158#M68015</link>
      <description>&lt;P&gt;It must be able to read security event logs.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 00:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186158#M68015</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-12T00:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186160#M68016</link>
      <description>&lt;P&gt;I will give that "option" to the client, because being a state entity, their policies are really a headache.&lt;BR /&gt;They don't want to provide a user from the "Event Log Readers" group, as a "precaution".&lt;BR /&gt;Hence my query.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 01:01:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186160#M68016</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-12T01:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186161#M68017</link>
      <description>&lt;P&gt;We all encounter clients like that, my friend : - )&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 01:08:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186161#M68017</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-12T01:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD Integration with Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186183#M68018</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;in a similar case we used the Identity Agent on the endpoint. You need local admin rights on the endpoint to install the agent but only for install. Agent can be configured to use SSO with the user authenticated on the endpoint.&lt;/P&gt;
&lt;P&gt;&lt;A title="Identity Agent for a User Endpoint Computer - Configuring as Identity Source" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Agent-for-Endpoint-Computer-Configuring-in-SmartConsole.htm?tocpath=Identity%20Agent%20for%20a%20User%20Endpoint%20Computer%20%7C_____1" target="_blank" rel="noopener"&gt;Identity Agent for a User Endpoint Computer - Configuring as Identity Source&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 05:24:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Integration-with-Checkpoint/m-p/186183#M68018</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-12T05:24:23Z</dc:date>
    </item>
  </channel>
</rss>

