- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
I believe that using AD Query is the quickest and easiest (and only way) to natively integrate MS AD MFA authentication and logging (MS AD Hybrid Connect mode) into the the SMB appliances running R80.20.30 on the Embedded Gaia OS?
Is that correct? Is Secure Platform 2.6 the same OS as Embedded Gaia in this article?
I notice that Radius Accounting and Identity Collector features that come with the full Gaia OS is not supported as per SK159772.
Many thanks.
You are correct, AD Query is the only option on SMB appliances beyond sharing identities from a non-SMB gateway.
SPLAT is legacy and is not the same as Embedded Gaia.
You are correct, AD Query is the only option on SMB appliances beyond sharing identities from a non-SMB gateway.
SPLAT is legacy and is not the same as Embedded Gaia.
Many thanks.
Hi Dameon,
Sorry two more clarifications:
-Can you confirm if the AD Query feature fully supports an Active Directory on-premise in Hybrid Connect Mode and also Azure AD in the cloud only? I don't believe it matters where the AD is located? On-premise or in the cloud?
- Can you confirm if MFA and SSO via MS Azure AD are fully supported by the AD Query feature on the SMB appliances? I can't find any documentation to show what MFA and SSO features the AD Query feature supports? Are these the correct links? ie on the SMB appliances do you get the full features of the Identity Awareness blade or is AD Query just a subset of the full Identity Awareness blade and MFA and SSO is not supported? In my mind as long as you can connect to the AD both MFA and SSO support should be seamless?
Many thanks for any extra insights?
Keep in mind AD Query does two things:
Which means it’s not directly processing the MFA at all, nor does it really care where AD sits provided it is accessible.
Whether this works with Hybrid Connect Mode or not is a different matter.
I’m assuming the LDAP piece will fail since SMB appliances do not currently support LDAP over SSL, which presumably will be required for any hosted AD.
Hello, thank you so can the SMB appliances support MS MFA with Azure AD and the Authenticator App out of the box and if so how is it done? This link below seems to imply yes but what are the pre-requisites? Can you show me an SK or some documentation in the MS Azure AD App Gallery that advises this for the SMB appliances?
Check Point Remote Access VPN with Azure Active Directory
The Check Point VPN is a tried-and-true solution which is now available in the Azure Active Directory (Azure AD) app gallery. Check Point VPN customers can now quickly enable single sign-on and manage access to the Check Point VPN with Azure AD.
By integrating with Azure AD, organizations can leverage capabilities such as Conditional Access and passwordless authentication to provide secure and seamless access to Check Point VPN.
By integrating with Azure AD, Check Point’s VPN solution can support advanced security capabilities that can help organizations on their Zero Trust journey.
Many thanks.
In that context, the answer is no, this will definitely not work on SMB appliances.
We only recently added this to our regular appliances running R80.40 and above in the recent JHFs.
More details here: https://community.checkpoint.com/t5/Remote-Access-VPN/SAML-Support-for-Remote-Access-VPN/m-p/117199
Many thanks. If a radius server and NPS was used would it work around this issue on the OS? https://sc1.checkpoint.com/documents/SMB_R80.20.30/AdminGuides/Centrally_Managed/EN/Topics/Managing-...
Solution design would be like this:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY