Hey bro,
You can do that, but please show them below. We had few customers with same concern and now they are so happy they went with collector and they are actually bit upset they had not done it sooner.
Andy
https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-...
These are the benefits of using Identity Collector instead of a standard AD QueryClosed:
Reduced load on the Security Gateway - Identity Collector does the queries instead of the Security Gateway
Reduced load on the Domain Controller (DC) - the native Windows API consumes fewer resources
Lower permissions required - Identity Collector requires read-only access to the domain security logs
No changes are required in the Active Directory (AD) schema.
One Identity Collector can serve multiple Security Gateways, even from a different Domain Management Servers on a Multi-Domain ServerClosed.
Identity Collector can communicate with a maximum of up to 35 Active Directory (AD) servers.
Identity Collector can process a maximum of 1900 Active Directory (AD) events per second.