- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
we are using endpoint security client with AD authentication.
we are working to avoid 2 times logins : one login/password to connect to the vpn , then the same for windows authentication.
is there a way to:
1- connect first to the vpn client with AD credential ( SDL) , then to "pass" the information to the windows login screen so that the user is logged ?
OR
2- login to windows login screen and then push the credentials (script,windows credentials).. to the endpoint client that automatically log to the vpn gw ?
thank you in advance.
we are using E80.x and R80.20 platforms
regards
The single sign on capabilities are tied to Check Point's implementation of Full Disk Encryption.
Xavier,
you should enable SecureDomainLogin on the VPN client.
With this you can start your VPN tunnel before you login to Windows and the credentials are passed to the windows logon.
There is no need to authenticate twice.
Wolfgang
hello Wolfgang,
thank you for your reply. SDL is already setup.
the user is connecting to the VPN client, then, he got the standard windows logon .. there is no "auto logon feature". is that something need to be actived somewhere ??
thank you,
best regards
xavier
Have a look at the client guide:
REMOTE ACCESS CLIENTS FOR WINDOWS 32/64-BIT E80.72 AND HIGHER
page 53, Secure Domain Logon (SDL)
Wolfgang
PS.: Do you have only VPN client installed or running with FDE in place ?
hello again,
the laptop is encrypted with bitlocker and the endpoint client E80.87 is installed.
maybe that's the reason ?
Not sure, but sounds the same:
Support for FDE SSO functionality and Explicit SDL on Endpoint Security Client
Wolfgang
Hey Wolfgang,
I know this post is a bit older but we have the same problem here. Endpoint Security Client 86.50 with SDL enabled.
The icon appears on the windows logon screen. I can connect to the vpn, but after that my windows logon must be done seperately. FDE or bitlocker is not active on our test client.
Regards
Auto-signin to Windows only works with FDE installed to the best of my knowledge.
Thanks for the quick reply. Our notebooks don´t support FDE but BitLocker encryption. Is this equal?
With active BitLocker there is no improvement.
Regards
The single sign on capabilities are tied to Check Point's implementation of Full Disk Encryption.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY