<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure Domain Logon unrealiable / users are too fast in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103505#M9592</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;we are using Checkpoint Endpoint Security (currently in E84.00 but, also had this with earlier versions). We are using Secure Domain Logon which is working as it should most of the time. Logon Prompt appears if the user is on an external network, no logon prompt if the user is at an internal network and so on.&lt;/P&gt;&lt;P&gt;We now have Conditional Access in place for M365 which relies on trusted locations, it's essential that the user logs on to VPN before any M365 services can be used, since using OneDrive and Teams Application is disallowed from untrusted locations (and OneDrive Autostarts if the user logs on).&lt;/P&gt;&lt;P&gt;The issue with SDL is, especially in the current panedmic scneario, that some users are simply too fast and logon as soon as the credential window appears... that's faster than the VPN client / service starts. We already have "Always wait for network..." active via GPO, but that does not really improve the situation. Telling the users to just wait like 10 seconds and then log on is also not quite satisfying.&lt;/P&gt;&lt;P&gt;Is there any idea, how the secure domain logon is reliably started before a user logs on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
    <pubDate>Fri, 27 Nov 2020 07:52:10 GMT</pubDate>
    <dc:creator>Velocy</dc:creator>
    <dc:date>2020-11-27T07:52:10Z</dc:date>
    <item>
      <title>Secure Domain Logon unrealiable / users are too fast</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103505#M9592</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;we are using Checkpoint Endpoint Security (currently in E84.00 but, also had this with earlier versions). We are using Secure Domain Logon which is working as it should most of the time. Logon Prompt appears if the user is on an external network, no logon prompt if the user is at an internal network and so on.&lt;/P&gt;&lt;P&gt;We now have Conditional Access in place for M365 which relies on trusted locations, it's essential that the user logs on to VPN before any M365 services can be used, since using OneDrive and Teams Application is disallowed from untrusted locations (and OneDrive Autostarts if the user logs on).&lt;/P&gt;&lt;P&gt;The issue with SDL is, especially in the current panedmic scneario, that some users are simply too fast and logon as soon as the credential window appears... that's faster than the VPN client / service starts. We already have "Always wait for network..." active via GPO, but that does not really improve the situation. Telling the users to just wait like 10 seconds and then log on is also not quite satisfying.&lt;/P&gt;&lt;P&gt;Is there any idea, how the secure domain logon is reliably started before a user logs on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 07:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103505#M9592</guid>
      <dc:creator>Velocy</dc:creator>
      <dc:date>2020-11-27T07:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon unrealiable / users are too fast</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103529#M9593</link>
      <description>&lt;P&gt;You did configure it following Remote Access VPN R80.40 Administration Guide p.139ff ? Another possibility is to use Machine Authentication, see Remote Access VPN R80.40 Administration Guide p.113.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 12:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103529#M9593</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-11-27T12:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon unrealiable / users are too fast</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103539#M9594</link>
      <description>&lt;P&gt;Thank you for the ideas.&lt;BR /&gt;About machine authentication, unfortunately compliance requests MFA with RSA Token, no change is possible to this at the moment.&lt;BR /&gt;Also yes, disabling cached credentials would actually prevent users from logging on at all without Domain Connections, but would also fully disable "offline usage" of the clients if there is no internet connection available (especially problematic if, for example the user needs to connect to a hotspot that requires additional steps)... so this is basically a no-go-&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 12:58:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103539#M9594</guid>
      <dc:creator>Velocy</dc:creator>
      <dc:date>2020-11-27T12:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon unrealiable / users are too fast</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103570#M9595</link>
      <description>&lt;P&gt;My understanding is this ties into specific Microsoft APIs that tie starting the VPN to logging in.&lt;BR /&gt;Sounds like it’s not and it might be worth a TAC case to troubleshoot this.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 02:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-unrealiable-users-are-too-fast/m-p/103570#M9595</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-28T02:42:59Z</dc:date>
    </item>
  </channel>
</rss>

