Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ArtemDanko
Explorer
Jump to solution

Identity Awareness not getting group membership with Identity Collector

Hi

Please help with troubleshooting of Identity Awareness on the vSEC gateway version 81.10 Take 335 JHF 95.

I have configured Identity Awareness with Identity Collector and MS Active Directory

When I made an Access Role for Domain Users and added it to the Source field of Access Control policy the test account didn't get access to the destination.

While troubleshooting this I noticed that gateway gets event of logged in test account but there is no information about its group membership.

When I try to login with my own account it gets that account is member of the group and access rule works.

Checking logs of blade "Identity Awareness" in SmartConsole I see that there are many users that are members of this group and many others - not.

Why it is and how to fix that? Thanks

0 Kudos
1 Solution

Accepted Solutions
Netanel_Cohen
Employee
Employee

Hello @ArtemDanko 

"Domain Users" is the default primary group for users in a domain.
Due to Microsoft's Implementation of the Active Directory server not returning primary groups, this group does not return in the response to our LDAP query.

See https://support.checkpoint.com/results/sk/sk32479 . 

View solution in original post

2 Replies
Netanel_Cohen
Employee
Employee

Hello @ArtemDanko 

"Domain Users" is the default primary group for users in a domain.
Due to Microsoft's Implementation of the Active Directory server not returning primary groups, this group does not return in the response to our LDAP query.

See https://support.checkpoint.com/results/sk/sk32479 . 

the_rock
Legend
Legend

K, just to make sure we are all on the same page here...are you saying that SOME users work fine, ie there are logs about their group membership and some dont work, though they belong to the same group?

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events