<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Login to SC with an AD user in &amp;quot;Protected Users Security Group&amp;quot; not possible in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136149#M24355</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as the title says, we currently face the problem that login to SC with AD-authentication is not possible, if the account is member of the group "Protected Users Security Group":&lt;/P&gt;&lt;P&gt;&lt;A href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fsecurity%2Fcredentials-protection-and-management%2Fprotected-users-security-group&amp;amp;data=04%7C01%7Camir.glibic%40atos.net%7C33346fa7966b4390d50808d9bbefa449%7C33440fc6b7c7412cbb730e70b0198d5a%7C0%7C0%7C637747460195676310%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;amp;sdata=yINdGtPCFw%2Fi%2FGx7FiffvMGy2Z%2Bf5C6SPnp71MPgCKE%3D&amp;amp;reserved=0" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Customer's admins are now in this group, which makes it impossible to manage the FW. Before implementing a workaround with a second account, I want to check if anyone has faced this before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this known behavior and is there any workaround?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THX in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 10:32:03 GMT</pubDate>
    <dc:creator>xiro</dc:creator>
    <dc:date>2021-12-13T10:32:03Z</dc:date>
    <item>
      <title>Login to SC with an AD user in "Protected Users Security Group" not possible</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136149#M24355</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as the title says, we currently face the problem that login to SC with AD-authentication is not possible, if the account is member of the group "Protected Users Security Group":&lt;/P&gt;&lt;P&gt;&lt;A href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fsecurity%2Fcredentials-protection-and-management%2Fprotected-users-security-group&amp;amp;data=04%7C01%7Camir.glibic%40atos.net%7C33346fa7966b4390d50808d9bbefa449%7C33440fc6b7c7412cbb730e70b0198d5a%7C0%7C0%7C637747460195676310%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;amp;sdata=yINdGtPCFw%2Fi%2FGx7FiffvMGy2Z%2Bf5C6SPnp71MPgCKE%3D&amp;amp;reserved=0" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Customer's admins are now in this group, which makes it impossible to manage the FW. Before implementing a workaround with a second account, I want to check if anyone has faced this before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this known behavior and is there any workaround?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THX in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136149#M24355</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2021-12-13T10:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Login to SC with an AD user in "Protected Users Security Group" not possible</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136208#M24367</link>
      <description>&lt;P&gt;SC = SmartConsole?&lt;BR /&gt;What version/JHF version?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 20:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136208#M24367</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-13T20:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Login to SC with an AD user in "Protected Users Security Group" not possible</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136212#M24369</link>
      <description>&lt;P&gt;yes, SmartConsole.&lt;/P&gt;&lt;P&gt;Server is 80.40 T125&lt;/P&gt;&lt;P&gt;SC was tested with different versions, including newest 80.40 build 425.&lt;/P&gt;&lt;P&gt;This is the configuration of the affected admins:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-12-13 220327.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14541iC22F18D227C1E135/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-12-13 220327.jpg" alt="Screenshot 2021-12-13 220327.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 21:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136212#M24369</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2021-12-13T21:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Login to SC with an AD user in "Protected Users Security Group" not possible</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136216#M24371</link>
      <description>&lt;P&gt;Suggest debugging fwm to see why it's failing:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86186" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86186&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You might need a TAC case to get to the bottom of it, though.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 21:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136216#M24371</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-13T21:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Login to SC with an AD user in "Protected Users Security Group" not possible</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136237#M24376</link>
      <description>&lt;P&gt;As you are using Radius for authentication the question is how is the Radius server authenticating against AD.&lt;/P&gt;
&lt;P&gt;Does this comply with protected users group? E.g. LDAP(S) is not!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 06:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Login-to-SC-with-an-AD-user-in-quot-Protected-Users-Security/m-p/136237#M24376</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-12-14T06:49:00Z</dc:date>
    </item>
  </channel>
</rss>

