- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Has anyone thought about or asked about the idea of AD based user groups for administration access?
The idea would be to have AD groups for full Admin control and another for Read-Only admin access.
The users would be added or removed in the AD groups and an administrator configuration would be built for the AD group not the individual users.
The AD groups can be managed for who is in there and have rights. There could be risks but also allows flexibility in Admin control.
Thoughts....
Personally for me I think that it's potentially opening up the platform and would become an additional security risk to consider. Obviously the level of risk would be dependant on how secure the Active Directory is.
Generally it would allow for anybody say with domain administrator access to be able to grant themselves access firewall management. Unless delegation was put in place over the AD groups. But on the other hand it would be a great way to manage access. Of the active directory was ever to be compromised this would then also put your firewall platform at risk also.
Having the permissions controlled by the SMS rather than AD is a lot more secure and would reduce the risk.
If it was available it would be a matter of weighing up the risk with the benefit.
Maybe if it ever does become available then delegating access to the as group that controls access to the firewall would become a best practice.
Those are my thoughts.
We use separate AD for infrastructure management so groups are tight and well controlled. Having to add/remove admins manually in CP is a hassle and likewise can lead to admins that are not removed after they have left the team. I vote AD groups. And direct AD integration. One point of control.
What about this question Multi-domain Admin user authentication to AD?
So in short Yes this question was asked recently.
I am not talking about authentication. I know you can do Radius to get AD auth. I am referring to having AD groups instead of users for Admin logins. Then populate the AD group. The issue is more to have a more central way to control admins instead of individual accounts.
Login by AD groups (and not just by single users) is also part of the solution we recently developed, that Maarten referred you to.
This solution, of authenticating administrators with AD, is currently in limited availability. So in order to get it, please approach Check Point solution center.
HI All,
Is there any update for this feature in latest R80.30 intakes? is there a plan to have this publicly released?
Hi
is this on the roadmap or already in R80.40?
Is there any other way to use a some kind of an admingroup instead of adding/removing every single admin for SmartConsole access?
CP_R80.40_Multi-DomainSecurityManagement_AdminGuide.pdf did not really help.
Thanks
Regards
Have you reviewed sk145392: SmartConsole Active Directory Authentication ?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY