<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN access restriction based on domain membership in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/84239#M14255</link>
    <description>&lt;P&gt;Hi Konstantinos&lt;/P&gt;&lt;P&gt;I finally got this working with SCV by using the below option. Please note when we login to our machines, based on the GPO we are placed under Users Group which has a AD group for domain users called "ABC\Domain Users", where ABC is your company domain. Unfortunately there was not a lot of documentation and examples of groupmonitor in either the admin guides, endpoint guides etc, but is working fine with this option below. This is a pretty strong SCV check and hard to fake compared to reg keys or process monitor checks (my 2 cents...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; : (groupmonitor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :type (plugin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :parameters (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :"builtin\Administrators" (false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :"builtin\Users=YOURCOMPANY\Domain Users" (true)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :begin_admin (admin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :send_log (alert)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :mismatchmessage ("Make sure you are logged on as an authorized user.")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :securely_configured_no_active_user (false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :end (admin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure to add this in the end for it to be effective,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :SCVPolicy (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (groupmonitor)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 15:59:22 GMT</pubDate>
    <dc:creator>Abd_S81</dc:creator>
    <dc:date>2020-05-05T15:59:22Z</dc:date>
    <item>
      <title>VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11069#M14240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I'm looking for an option to restrict VPN access only for laptops which are "domain members".&lt;/P&gt;&lt;P&gt;Is there a way to accomplish that? (All PCs/Part of them?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Nov 2017 20:14:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11069#M14240</guid>
      <dc:creator>Alexander_Urits</dc:creator>
      <dc:date>2017-11-12T20:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11070#M14241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, there's an option in the Endpoint Security VPN client called "Secure Configuration Verification" (SCV).&lt;/P&gt;&lt;P&gt;One of the checks you can configure is "Verifies that the user logged into the operating system and is a member of specified Domain User Groups."&lt;/P&gt;&lt;P&gt;That should meet your specific requirement.&lt;/P&gt;&lt;P&gt;Note this only applies to Windows PCs as the Mac VPN client does not support these checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_RemoteAccessVPN_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_RemoteAccessVPN_AdminGuide/html_frameset.htm"&gt;Remote Access VPN R80.10 (Part of Check Point Infinity)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 04:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11070#M14241</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-13T04:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11071#M14242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two additional questions:&lt;/P&gt;&lt;P&gt;1. Does that require specific VPN client license/flavor?&lt;/P&gt;&lt;P&gt;2. How do I enforce that only this type of client can connect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 05:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11071#M14242</guid>
      <dc:creator>Alexander_Urits</dc:creator>
      <dc:date>2017-11-13T05:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11072#M14243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It requires the Endpoint Security VPN client, which requires a remote access VPN license for each user that connects.&lt;/P&gt;&lt;P&gt;In terms of our current Endpoint licenses, this includes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Endpoint Access Control&lt;/LI&gt;&lt;LI&gt;Endpoint Complete&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, other legacy licenses may include this .&lt;/P&gt;&lt;P&gt;If you have questions about this, reach out to your Check Point account team or Partner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The procedure for enforcing that only that client can connect includes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Defining the SCV policy appropriately&lt;/LI&gt;&lt;LI&gt;Preventing clients that are NOT Endpoint Security VPN from connecting&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This should be covered in the documentation I linked previously.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 05:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11072#M14243</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-13T05:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11073#M14244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apparently SCV policy is a global property, and if the customer has more than one gateway or more different policies for different type of users it's not possible, at least I couldn't find any documentation on this and support guys didn't also.&lt;/P&gt;&lt;P&gt;Anyone who has any field experience with the SCV policy, please comment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2018 22:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11073#M14244</guid>
      <dc:creator>Alexander_Urits</dc:creator>
      <dc:date>2018-05-03T22:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11074#M14245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you manage to accomplish&amp;nbsp;this in the end?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2018 20:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11074#M14245</guid>
      <dc:creator>Darran_Lebas</dc:creator>
      <dc:date>2018-11-21T20:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11075#M14246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Hi Darran.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Unfortunately there was no workaround.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;I was forced to implement this for all the gateways.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Regards,&lt;/P&gt;&lt;P class=""&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 14:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11075#M14246</guid>
      <dc:creator>Alexander_Urits</dc:creator>
      <dc:date>2018-11-22T14:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11076#M14247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Other way of achieving your requirement (Only Domain users can connect remote VPN) is that you can enable Mobile access blade and create Native application for Domain check.&lt;/P&gt;&lt;P&gt;You need to enable Endpoint security scan check in Mobile access blade and create Native application for Domain check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is long process but it is very stable. I have enabled this scenario for one customer and it is working fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 09:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/11076#M14247</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-11-23T09:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/48266#M14248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;can we restrict with windows domain member for example&amp;nbsp; : allow the only machine which is in abc.com &amp;amp; sampla.com&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 13:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/48266#M14248</guid>
      <dc:creator>mahendran_B1</dc:creator>
      <dc:date>2019-03-22T13:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/48281#M14249</link>
      <description>Yes, please see the docs I linked previously.</description>
      <pubDate>Fri, 22 Mar 2019 13:39:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/48281#M14249</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-22T13:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/49275#M14250</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;By group monitor, we can restrict allow only based on domain member.At endpoint&amp;nbsp;side, the secure client is enough or i need to install endpoint security.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 11:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/49275#M14250</guid>
      <dc:creator>mahendran_B</dc:creator>
      <dc:date>2019-03-30T11:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/50241#M14251</link>
      <description>&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm below configuration for domain monitor in local.scv file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;: (groupmonitor&lt;BR /&gt;:type (plugin)&lt;BR /&gt;:parameters (&lt;BR /&gt;:begin_or (or1)&lt;BR /&gt;:begin_and (1)&lt;BR /&gt;:&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;mydomian.com (true)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;:end (1)&lt;BR /&gt;:end (or1)&lt;BR /&gt;:begin_admin (admin)&lt;BR /&gt;:send_log (alert)&lt;BR /&gt;:mismatchmessage ("You are using SecureClient with a non-authorized user.\nMake sure you are logged on as an authorized user.")&lt;BR /&gt;:securely_configured_no_active_user (false)&lt;BR /&gt;:end (admin)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 06:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/50241#M14251</guid>
      <dc:creator>mahendran_B</dc:creator>
      <dc:date>2019-04-09T06:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/50312#M14252</link>
      <description>&lt;P&gt;What I need to is to only allow domain users to connect to VPN who are using corporate machines. Mac and Linux machines would be great but I at least need to check the Windows machines which will be joined to our corporate domain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 13:43:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/50312#M14252</guid>
      <dc:creator>shenderson</dc:creator>
      <dc:date>2019-04-09T13:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/55277#M14253</link>
      <description>Hi Gaurav,&lt;BR /&gt;I have the same issue, i am not able to create Native Application for Domain Check. Can i have the steps to do it? Can you guide me from Native Applications step because i can see this option but not sure how to create Domain Check.&lt;BR /&gt;Many thanks in advance.</description>
      <pubDate>Fri, 07 Jun 2019 13:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/55277#M14253</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2019-06-07T13:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/83471#M14254</link>
      <description>Hello mahendran_B&lt;BR /&gt;&lt;BR /&gt;The options you have are the below. Did you finally configured it?&lt;BR /&gt;&lt;BR /&gt;: (groupmonitor&lt;BR /&gt;:type (plugin)&lt;BR /&gt;:parameters (&lt;BR /&gt;:begin_or (or1)&lt;BR /&gt;:begin_and (1)&lt;BR /&gt;:"builtin\administrator" (false)&lt;BR /&gt;:"BUILTIN\Users" (true)&lt;BR /&gt;:end (1)&lt;BR /&gt;:begin_and (2)&lt;BR /&gt;:"builtin\administrator" (true)&lt;BR /&gt;:"BUILTIN\Users" (false)&lt;BR /&gt;:end (and2)&lt;BR /&gt;:end (or1)&lt;BR /&gt;:begin_admin (admin)&lt;BR /&gt;:send_log (alert)&lt;BR /&gt;:mismatchmessage ("You are using SecureClient with a non-authorized user.\nMake sure you are logged on as an authorized user.")&lt;BR /&gt;:securely_configured_no_active_user (false)&lt;BR /&gt;:end (admin)&lt;BR /&gt;)&lt;BR /&gt;)&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Apr 2020 10:56:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/83471#M14254</guid>
      <dc:creator>Konstantinos_In</dc:creator>
      <dc:date>2020-04-28T10:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/84239#M14255</link>
      <description>&lt;P&gt;Hi Konstantinos&lt;/P&gt;&lt;P&gt;I finally got this working with SCV by using the below option. Please note when we login to our machines, based on the GPO we are placed under Users Group which has a AD group for domain users called "ABC\Domain Users", where ABC is your company domain. Unfortunately there was not a lot of documentation and examples of groupmonitor in either the admin guides, endpoint guides etc, but is working fine with this option below. This is a pretty strong SCV check and hard to fake compared to reg keys or process monitor checks (my 2 cents...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; : (groupmonitor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :type (plugin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :parameters (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :"builtin\Administrators" (false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :"builtin\Users=YOURCOMPANY\Domain Users" (true)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :begin_admin (admin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :send_log (alert)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :mismatchmessage ("Make sure you are logged on as an authorized user.")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :securely_configured_no_active_user (false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :end (admin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure to add this in the end for it to be effective,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :SCVPolicy (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (groupmonitor)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 15:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/84239#M14255</guid>
      <dc:creator>Abd_S81</dc:creator>
      <dc:date>2020-05-05T15:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/85386#M14256</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Thank you for your response &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; .We are in the same page.&lt;/P&gt;&lt;P&gt;It is not very hard to fake the domain if you create a domain controller and a same domain name with the corporate you want to "attack".&lt;/P&gt;&lt;P&gt;As concerns processes just a rename does the bypass..&lt;/P&gt;&lt;P&gt;As concerns registry key i don't know if there is a way to find somehow the "required" keys in order to connect and pass compliance "client side"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 14:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/85386#M14256</guid>
      <dc:creator>Konstantinos_In</dc:creator>
      <dc:date>2020-05-15T14:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127067#M14257</link>
      <description>&lt;P&gt;i'm also struggling with ad scv at the moment. did you find any documentation on this topic, or where do you have your syntax from?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 11:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127067#M14257</guid>
      <dc:creator>Myx</dc:creator>
      <dc:date>2021-08-16T11:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127144#M14258</link>
      <description>&lt;P&gt;This thread might help:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Real-World-local-scv-Example/m-p/81381#M3084" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Real-World-local-scv-Example/m-p/81381#M3084&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 23:11:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127144#M14258</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-16T23:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access restriction based on domain membership</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127177#M14259</link>
      <description>&lt;P&gt;thank you for your fast reply. i've already seen the domain check via registry. but i thought the check via the groupmonitor was a bit more secure.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 06:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-access-restriction-based-on-domain-membership/m-p/127177#M14259</guid>
      <dc:creator>Myx</dc:creator>
      <dc:date>2021-08-17T06:52:03Z</dc:date>
    </item>
  </channel>
</rss>

