Using Identity Awareness and access roles
Prior to 2021, the easiest way to demonstrate Identity Awareness with an external user directory was to use the AD Query method. Unfortunately, due to the discovery of Microsoft’s vulnerability CVE-2021-26414, Check Point had to deprecate this feature. It is still available to accommodate existing customers that are slow to migrate to a better solution, but being bad practice, I’d like to avoid it. Now, the appropriate way to implement Identity Awareness is to deploy Identity Collector. This is a more serious undertaking that we do not have space for and is a slightly more advanced subject. If you’d like to learn more about it, see sk108235 Identity Collector – Technical Overview. The other way for me to demonstrate it here is to use Browser-Based Authentication.
Note
To learn more about the reasons for AD Query deprecation and Microsoft’s deadline for the retirement of WMI features, read the sk176148...