Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tavi0906
Contributor

do we need domain admin rights for the service account in Identity awareness

do we need domain admin rights for the service account in Identity awareness

0 Kudos
8 Replies
Chris_Atkinson
Employee Employee
Employee

Please explore Identity Collector further as the preferred method.

Identity Collector - Requirements (checkpoint.com)

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Im fairly sure you do. Though below sk, if you can make it work, should suffice, but I was never able to get it going, even with TAC on the phone.

Andy

https://support.checkpoint.com/results/sk/sk93938

0 Kudos
cassiomaciel
Contributor

@tavi0906  you can use the sk93938 mentioned by @the_rock .

 

I'm using ad query in my enviroment and it's working properly.

You must configure the permissions for the service account in all ad servers, it's not necessary be a domain admin.

 

 

 

0 Kudos
the_rock
Legend
Legend

If you got that sk going, then it sefinitely would work : - )

I dont know, I was never able to succeed at it, even with TAC help.

Andy

0 Kudos
tavi0906
Contributor

why do we need the domain admin rights for service account ? any reason  ?

 

0 Kudos
Alex-
Leader Leader
Leader

It is not if you use the Identity Collector, and you should, as per the documentation that @Chris_Atkinson shared:

 

Requirements for Integration with Active Directory

Windows Server must connect to the Active Directory (AD) domain controllers of the organization with DNS, LDAP, and DCOM.

The Identity Collector requires an Active Directory (AD) user that belongs to the default Event Log Readers group.


Note - An administrative role is not required for this user.

 

0 Kudos
the_rock
Legend
Legend

According to the sk we shared, you do not need an account with admin right, but as I said, I tried this with few different clients (TAC was on the phone every time) and we could never get it working. Clearly, we missed something... : - )

Andy

0 Kudos
Vincent_Bacher
Advisor
Advisor

You are talking about LDAP AU or something different?
For LDAP AU admin permissions are not required.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events