- CheckMates
- :
- Products
- :
- General Topics
- :
- Identity awareness deployment for Non-AD Member
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity awareness deployment for Non-AD Member
Here's the scenario - the customer management would like to restrict the corporate users on using non-domain laptops when connecting to the corporate network. Only domain managed devices can be allowed, non-domain laptop should be restricted even the corporate user entered the correct corporate domain credentials to the captive portal, their access should be denied because the device is unmanaged by the AD.
Can we implement this kind of use case? are there any option on Identity Awareness that can we install like an agent and check the user endpoint if part of AD or not?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, e.g. by SSO: https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Access Roles can include machine identity, which will only exist for machines in AD.
This should allow you to create more restrictive rules for users on machines not on AD.
