- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello Checkmate,
Is windows server 2025 can be used to configure Identity Awarness?
This SK does not saying nothing about it : sk108235 - Identity Collector - Technical Overview
But I get this in the log when IC tries Identity Propagation : "An error was detected while trying to authenticate against the AD server. It may be a problem of bad configuration or connectivity. Please refer to the troubleshooting guide for more help"
In my Identity Collector configuration, my identity Sources (DCs on windows server 2025) are active, It receive Event and the status is Connected. The Identity Server (the FW 1600 appliance) seems Connected).
Please advise if you have any information about this.
Thanks
I'd check some of what's mentioned in this SK: https://support.checkpoint.com/results/sk/sk164834
In general Identity Collector support for Windows Server 2025 is confirmed in sk134312
I'd check some of what's mentioned in this SK: https://support.checkpoint.com/results/sk/sk164834
Thank you all for the contribution.
I'll try to activate LDAPS when configuring LDAP account in smart console.
In general Identity Collector support for Windows Server 2025 is confirmed in sk134312
Where exactly do you see the error
"An error was detected while trying to authenticate against the AD server. It may be a problem of bad configuration or connectivity. Please refer to the troubleshooting guide for more help"
I guess you can see this in SmartLog and the error is generated by the gateway, correct? It also attempts to connect to the AD server in order to obtain the group memberships, including nested groups, via one or multiple LDAP queries so that it can determine the access roles of the session or user.
At least, that is how it works when a user comes in via IA agent, and it should be the same with IDC.
Will see if I can find a post someone made about it recently where they were using windows server 2025, but looks like sk Chris gave confirms it.
I would still want to look into the error message mentioned; I think it should be eliminated if possible.
Agree 100%, Vince. Let me see if we have windows server 2025 image spun up in eve ng, I can try it later.
I guess this message is not really related to the windows server release but more likely to the AU config but I may be wrong.
If I may, I would like to explain the reason for my message. It is my understanding that this message is well known in our organisation and is usually caused by issues in the AU configuration or the missing AU or LDAP query option.
However, given that we do not use IDC to connect to AD, it is possible that the situation here differs. I may of course be mistaken.
Not sure if this could be related, but I did quick AI search and below is what it gave me...worth checking:
That exact SmartLog error is generally tied to LDAP/Account Unit configuration issues. Check Point’s SK for this message states the cause is LDAP configuration-related, with multiple possible reasons. [supportcen...kpoint.com]
Given your environment (DCs on Windows Server 2025), the most likely reason is:
✅ The gateway is trying to talk to AD using LDAP (389) or non-SSL settings, but AD 2025 requires LDAPS for the Identity Awareness gateway connection. [sc1.checkpoint.com]
That is basically exactly what I explained above, correct?
Yep, you got it. Not saying that is exact reason, but seems related.
LDAP/LDAPS is one of the reasons I faced before. Simple things like wrong user/pass or just locked account of the user are other faced issues but most of them related to the AU
My experience is more less the same. Definitely worth double checking on it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY