<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD query failing for identity Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179887#M5083</link>
    <description>&lt;P&gt;Excellent point indeed...I had customer who was hesitant to move to IDC, but once I gave them all the good reasons to and they saw issues with windows updates on their AD server, they finally accepted to move away from AD query and are super content now with identity collector, no issues on 3 months since the change.&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2023 18:01:18 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-03T18:01:18Z</dc:date>
    <item>
      <title>AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179723#M5076</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;We have recently had to rebuild our r77.30 firewall (due to a failed upgrade attempt, SMS is already r81).&lt;/P&gt;&lt;P&gt;We have connectivity from r77.30 gw to our RSA server but get the following error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AD Query.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20731i25A110002D6F5618/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AD Query.JPG" alt="AD Query.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried several sets of creds which we know to be correct (i.e. admin level) but continue to get this error message.&lt;/P&gt;&lt;P&gt;Can anyone help please?&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 15:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179723#M5076</guid>
      <dc:creator>checkpointer</dc:creator>
      <dc:date>2023-05-02T15:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179729#M5077</link>
      <description>&lt;P&gt;For simplicity, the service account you use with the IDA should be a Domain Admin. It is possible to use a non-Domain Admin account, but then you need to start doing schema updates and changes within your Domain. Not familiar with pointing IDA at a RSA server vs a domain/domain controller.&lt;/P&gt;
&lt;P&gt;Also do need to point out that R77.30 has been End of Support for a while now. R80.40 is our oldest/supported version with R81.10 being our Recommended version.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 16:09:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179729#M5077</guid>
      <dc:creator>Matt_Ricketts</dc:creator>
      <dc:date>2023-05-02T16:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179735#M5078</link>
      <description>&lt;P&gt;Put it this way...as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/559"&gt;@Matt_Ricketts&lt;/a&gt;&amp;nbsp;said, R77.30 has been unsupported way before Covid-19 I think, but regardless, even if you were on R55 or R81.20 version, you HAVE TO use domain account with full admin privileges to make this work. I spent way too many hours with TAC on the phone going through sk93938 and we could never get that working...ever.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk93938" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk93938&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 18:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179735#M5078</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T18:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179755#M5079</link>
      <description>&lt;P&gt;Thanks Matt, the&amp;nbsp;&lt;SPAN&gt;account we are testing with are both Domain Admin.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 23:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179755#M5079</guid>
      <dc:creator>checkpointer</dc:creator>
      <dc:date>2023-05-02T23:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179756#M5080</link>
      <description>&lt;P&gt;Thanks Rock, the&amp;nbsp;&lt;SPAN&gt;accounts we are testing with are domain accounts with full admin privileges.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 23:22:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179756#M5080</guid>
      <dc:creator>checkpointer</dc:creator>
      <dc:date>2023-05-02T23:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179763#M5081</link>
      <description>&lt;P&gt;Windows Server 2016 or 2019? Microsoft changed things within Windows Server 2022 and my IDA wouldn't authenticate anymore. I changed to the Identity Collector at that point. IDC is moving towards being the recommended method going forward too.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 23:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179763#M5081</guid>
      <dc:creator>Matt_Ricketts</dc:creator>
      <dc:date>2023-05-02T23:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179886#M5082</link>
      <description>&lt;P&gt;In response to various security vulnerabilities, Microsoft has made numerous changes to WMI.&lt;BR /&gt;This effectively "breaks" ADQuery and we've been recommending people move to Identity Collector for some time.&lt;BR /&gt;For details on Identity Collector, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108235" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108235&lt;/A&gt;&lt;BR /&gt;Yes, you can run Identity Collector under R77.30, but it's been End of Support for other three years now.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 17:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179886#M5082</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-03T17:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: AD query failing for identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179887#M5083</link>
      <description>&lt;P&gt;Excellent point indeed...I had customer who was hesitant to move to IDC, but once I gave them all the good reasons to and they saw issues with windows updates on their AD server, they finally accepted to move away from AD query and are super content now with identity collector, no issues on 3 months since the change.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-query-failing-for-identity-Awareness/m-p/179887#M5083</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T18:01:18Z</dc:date>
    </item>
  </channel>
</rss>

