- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I have a scenario where users had local accounts created on firewall and now we have created user accounts in the Active Directory. The local accounts are to be deleted and all users should authenticate via AD only in future. To avoid disruption and migrate all the AD based accounts smoothly, how to identify if user is authenticating locally or via AD.
In the logs you can check after the Key install logs, for the Decrypt packets and the field called Src User Dn which should contain the full path for the user in AD.
You would require to do a ActiveDirectory query for all users and get the distinguishedName attribute.
It's basically the full path to which the AD user is found in the Forest/Domain .
Try in SVTracker to show the column, filter and export.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY