<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing sync of AD security group from endpoint server in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149022#M5660</link>
    <description>&lt;P&gt;Greetings all !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use a security group in my AD to pinpoint workstations&amp;nbsp;eligible for FDE.&amp;nbsp; Thus I have rule,&amp;nbsp; where an AD security group is the dynamic "target"&amp;nbsp; -&amp;nbsp;This has worked out perfectly so far.&lt;/P&gt;&lt;P&gt;Alas (otherwise i wouldnt be writing this post) the "link" seems broken to the AD security group.&lt;BR /&gt;&lt;BR /&gt;I can see worksstations in my AD - but when looking into the deployment rules - the reflection of the group are missing several members .&lt;/P&gt;&lt;P&gt;As i understand - using security group for deployment secures dynamic updates - where virtual groups lack that ability.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;I have other rules depending on the AD connection - whích works fine - but those are based on virtual groups instead of Security groups.&lt;BR /&gt;&lt;BR /&gt;I have tried removing said group and reapply it - to no avail.&lt;BR /&gt;&lt;BR /&gt;I feel confident the connection between server and AD is at least partial working - since i can browse my AD from endpoint server.&lt;BR /&gt;&lt;BR /&gt;Hope this makes sense !&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2022 12:56:42 GMT</pubDate>
    <dc:creator>Peter_Bjeldbak</dc:creator>
    <dc:date>2022-05-19T12:56:42Z</dc:date>
    <item>
      <title>Missing sync of AD security group from endpoint server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149022#M5660</link>
      <description>&lt;P&gt;Greetings all !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use a security group in my AD to pinpoint workstations&amp;nbsp;eligible for FDE.&amp;nbsp; Thus I have rule,&amp;nbsp; where an AD security group is the dynamic "target"&amp;nbsp; -&amp;nbsp;This has worked out perfectly so far.&lt;/P&gt;&lt;P&gt;Alas (otherwise i wouldnt be writing this post) the "link" seems broken to the AD security group.&lt;BR /&gt;&lt;BR /&gt;I can see worksstations in my AD - but when looking into the deployment rules - the reflection of the group are missing several members .&lt;/P&gt;&lt;P&gt;As i understand - using security group for deployment secures dynamic updates - where virtual groups lack that ability.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;I have other rules depending on the AD connection - whích works fine - but those are based on virtual groups instead of Security groups.&lt;BR /&gt;&lt;BR /&gt;I have tried removing said group and reapply it - to no avail.&lt;BR /&gt;&lt;BR /&gt;I feel confident the connection between server and AD is at least partial working - since i can browse my AD from endpoint server.&lt;BR /&gt;&lt;BR /&gt;Hope this makes sense !&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 12:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149022#M5660</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2022-05-19T12:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Missing sync of AD security group from endpoint server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149039#M5661</link>
      <description>&lt;P&gt;I would suggest to contact TAC to resolve this issue !&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 14:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149039#M5661</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-19T14:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Missing sync of AD security group from endpoint server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149229#M5672</link>
      <description>&lt;P&gt;Do you have an AD Scanner running?&lt;BR /&gt;Secondly, the AD Scanner only checks in a frequency of 120 Minutes (TAC told me there is no shorter time span possible) for any changes in AD and syncs that into the CP DB.&lt;/P&gt;&lt;P&gt;This means that if you change a AD security group and add a Client - it can be up to 120min Delay in worst cases until CP notices that ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR ME&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 09:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149229#M5672</guid>
      <dc:creator>Michi</dc:creator>
      <dc:date>2022-05-23T09:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Missing sync of AD security group from endpoint server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149265#M5676</link>
      <description>&lt;P&gt;SOLVED !!&lt;BR /&gt;&lt;BR /&gt;So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)&lt;BR /&gt;&lt;BR /&gt;After contacting suppport - I ended up with the below suggestion.&lt;BR /&gt;&lt;BR /&gt;1. Enter SSH to the Endpoint Management Server.&lt;BR /&gt;2. cpstop&lt;BR /&gt;3. cd $UEPMDIR/engine/uepm-jms-data&lt;BR /&gt;4. rm *&lt;BR /&gt;5. cpstart&lt;BR /&gt;&lt;BR /&gt;Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!&lt;BR /&gt;&lt;BR /&gt;kind regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 14:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Missing-sync-of-AD-security-group-from-endpoint-server/m-p/149265#M5676</guid>
      <dc:creator>Peter_Bjeldbak</dc:creator>
      <dc:date>2022-05-23T14:08:30Z</dc:date>
    </item>
  </channel>
</rss>

