<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enable SCV in Remote Access VPN client for macOS in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259803#M1286</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;My customer would like to restrict macOS devices that are not joined to the AD domain from connecting to VPN through Endpoint Agent.&lt;/P&gt;&lt;P&gt;According to SK182226, I understand that it’s possible to configure relevant rules to achieve this control. However, I’m not sure which parameter specifically corresponds to the AD domain membership check.&lt;/P&gt;&lt;P&gt;If anyone has experience with this configuration, I’d really appreciate your guidance or advice.&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Tue, 14 Oct 2025 03:50:01 GMT</pubDate>
    <dc:creator>Vanness_Chen</dc:creator>
    <dc:date>2025-10-14T03:50:01Z</dc:date>
    <item>
      <title>Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259803#M1286</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;My customer would like to restrict macOS devices that are not joined to the AD domain from connecting to VPN through Endpoint Agent.&lt;/P&gt;&lt;P&gt;According to SK182226, I understand that it’s possible to configure relevant rules to achieve this control. However, I’m not sure which parameter specifically corresponds to the AD domain membership check.&lt;/P&gt;&lt;P&gt;If anyone has experience with this configuration, I’d really appreciate your guidance or advice.&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 03:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259803#M1286</guid>
      <dc:creator>Vanness_Chen</dc:creator>
      <dc:date>2025-10-14T03:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259870#M1287</link>
      <description>&lt;P&gt;&amp;nbsp;Not sure if this makes sense, but here is AI response.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*****************&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="8" data-end="309"&gt;To achieve the desired control of restricting macOS devices that are not joined to the AD domain from connecting to the VPN through Endpoint Agent, you are on the right track by referencing the rules described in SK182226. This document outlines how to configure policies to enforce device compliance.&lt;/P&gt;
&lt;P data-start="311" data-end="548"&gt;The key parameter you are looking for in this context is the &lt;STRONG data-start="372" data-end="395"&gt;"Domain Membership"&lt;/STRONG&gt; check. Specifically, you're aiming to check whether the macOS device is joined to your Active Directory domain, and if it's not, deny access to the VPN.&lt;/P&gt;
&lt;P data-start="550" data-end="602"&gt;Here’s a rough outline of what you might need to do:&lt;/P&gt;
&lt;OL data-start="604" data-end="1709"&gt;
&lt;LI data-start="604" data-end="1006"&gt;
&lt;P data-start="607" data-end="642"&gt;&lt;STRONG data-start="607" data-end="642"&gt;Configure Endpoint Agent Rules:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="646" data-end="1006"&gt;
&lt;LI data-start="646" data-end="762"&gt;
&lt;P data-start="648" data-end="762"&gt;Within the &lt;STRONG data-start="659" data-end="688"&gt;Endpoint Security profile&lt;/STRONG&gt;, you will configure rules to check the system's domain membership status.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="766" data-end="1006"&gt;
&lt;P data-start="768" data-end="1006"&gt;The &lt;STRONG data-start="772" data-end="796"&gt;AD Domain Membership&lt;/STRONG&gt; check is generally based on the presence of specific domain-joined attributes (such as the domain, organizational unit, or computer name) on the device. This can be defined within the security policy settings.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="1008" data-end="1404"&gt;
&lt;P data-start="1011" data-end="1041"&gt;&lt;STRONG data-start="1011" data-end="1041"&gt;Custom Rule Configuration:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1045" data-end="1404"&gt;
&lt;LI data-start="1045" data-end="1218"&gt;
&lt;P data-start="1047" data-end="1218"&gt;In the relevant rule set, you can define a custom &lt;STRONG data-start="1097" data-end="1120"&gt;"Domain Membership"&lt;/STRONG&gt; condition that ensures that only devices joined to the AD domain can pass the VPN authentication.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1222" data-end="1404"&gt;
&lt;P data-start="1224" data-end="1404"&gt;The &lt;STRONG data-start="1228" data-end="1241"&gt;AD Domain&lt;/STRONG&gt; check will typically use the device’s hostname or domain information as a condition, ensuring that the endpoint meets the necessary domain membership requirement.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="1406" data-end="1709"&gt;
&lt;P data-start="1409" data-end="1436"&gt;&lt;STRONG data-start="1409" data-end="1436"&gt;Testing and Validation:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1440" data-end="1709"&gt;
&lt;LI data-start="1440" data-end="1575"&gt;
&lt;P data-start="1442" data-end="1575"&gt;After configuring the rules, make sure to test with devices that are both domain-joined and non-domain-joined to verify the behavior.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1579" data-end="1709"&gt;
&lt;P data-start="1581" data-end="1709"&gt;You can also leverage system logs on the Endpoint Agent to confirm that the domain membership check is correctly being enforced.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="1711" data-end="2031"&gt;If your specific setup involves third-party VPN solutions or additional security layers, the exact parameter name or configuration might differ. That being said, I would recommend reviewing the most recent VPN and Endpoint Agent documentation from your vendor (if applicable) for any updates or specific syntax required.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 23:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259870#M1287</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-14T23:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259873#M1288</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;I’ve reviewed SK182226, which mentions that the SCV feature for macOS is supported, but it is disabled by default and requires the client to manually enable it (as described in Step 2).&lt;/P&gt;&lt;P&gt;Given this behavior, does it mean that we cannot use SCV to block unmanaged or unknown macOS devices in the current situation?&lt;/P&gt;&lt;P&gt;Also, does the SCVGlobalParams parameter — specifically "allow_non_scv_clients (false)" — apply to macOS clients as well?&lt;/P&gt;&lt;P&gt;According to this discussion thread:&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; How to enable Secure Client Verification&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/How-to-enable-Secure-Client-Verification/td-p/131860" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/How-to-enable-Secure-Client-Verification/td-p/131860&lt;/A&gt;&lt;/P&gt;&lt;P&gt;it seems there isn’t a clear or definitive answer.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 02:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259873#M1288</guid>
      <dc:creator>Vanness_Chen</dc:creator>
      <dc:date>2025-10-15T02:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259875#M1289</link>
      <description>&lt;P&gt;Yes, not 100% clear...I woukd definitely confirm with TAC.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 02:41:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259875#M1289</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-15T02:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259905#M1290</link>
      <description>&lt;P&gt;Hi Vanness,&lt;/P&gt;
&lt;P&gt;I did a write up on how to enable domain membership checks via SCV for Windows Clients - I know you mentioned Macs but this should provide a good starting point.&amp;nbsp; I know when I did it the first time I was wishing for slightly clearer documentation.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://namitguy.blogspot.com/2020/04/implementing-secure-client-verification.html" target="_blank"&gt;https://namitguy.blogspot.com/2020/04/implementing-secure-client-verification.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;-Ruan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 10:46:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/259905#M1290</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-10-15T10:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SCV in Remote Access VPN client for macOS</title>
      <link>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/260020#M1291</link>
      <description>&lt;P&gt;Wow...EXCELLENT!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 06:14:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Enable-SCV-in-Remote-Access-VPN-client-for-macOS/m-p/260020#M1291</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-16T06:14:38Z</dc:date>
    </item>
  </channel>
</rss>

