- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Experts,
From the very first beginning Active Directory Query is configured using the Mobile Access Wizard.
Nowadays I’am using the Identity Collector and want to get rid of the Active Directory Query configuration and the LDAP Account unit (checkpoint.lab__AD).
When I open the LDAP account unit and open the open “Where Used” I see it’s only used in the gateway configuration.
On the gateway object the option “Active Directory Query” is greyed out, so I cannot deactivate this option.
When I open the settings and removing the LDAP Account Unit (checkpoint.lab__AD) and click OK, the following warning is displayed.
And when clicking OK
Domain to query is not selected will be displayed, so there is no option to deactivate Active Directory Query at this point..
Any suggestions how to deactivate Active Directory Query?????
I have tried several options but without success…..
If you disable the IA blade and then enable it again, the Mobile Access Wizard will let you enable IA without AD Query.
No, it is in the wizard also greyed out
There is probably still a reference to the AU object in the Mobile Access Blade in the SmartDashboard; I don't think Where Used will show references in the legacy SmartDasboard so I suspect that's why it is greyed out everywhere in SmartConsole. Try poking around in the legacy SmartDashboard.
I had that exact issue before and I solved it by removing some IA references in guidbedit for AD Cant recall what, but will update if I find out.
Thanks!!
Hi @MarkWeber ,
This happens probably since you have Identity Logging enabled on the "Management" Tab.
Identity Logging is basically same as AD Query, but running on the mgmt side to enrich the management logs, without any enforcement abilities.
As for your specific issue, please disable Identity Logging on the mgmt tab first, and afterwards disable AD Query.
A general note for all Identity Awareness customers which are using AD integration such as AD Query and Identity Collector: there is no need to enable Identity Logging in addition to that. One of the Identity Awareness targets is anyhow enrich the management logs, together with enforcing traffic according to identities. It means, in other words, that ADQ / IDC will do logging + enforcement while Identity Logging is doing only logging.
Hi Royi,
You're the EXPERT!!! That was the solution, disabled the Identity Logging feature and now I'am able to disable AD Query.
Thanks a lot.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY