Directory Sync with Active Directory

The Directory SyncClosed A solution that holds static Directory information regarding users, groups, devices, and memberships. . feature automates the alignment of user accounts, groups, and devices between an on-premises Active Directory server and the Check Point Portal. It ensures data consistency and accuracy by reflecting changes in Active Directory directly in the Check Point Portal. This eliminates manual updates, prevents errors, and ensures administrators always work with current user and group information.

Prerequisites

Known Limitation

A maximum of 300,000 members in one Active Directory group is supported.

Use Case

Challenge:

Manual updates to user accounts, group assignments, and device information consume significant time and introduce risks of errors.

Solution:

Use Directory Sync to automate synchronization of user details, group memberships, and device information. This approach ensures accurate records, simplifies access control, and maintains an updated inventory of associated devices, which improves both efficiency and security.

Architecture

This drawing illustrates the Identity Collector configured with Directory Sync. It extracts user, group, and identity data directly from the Active Directory source and transmits the information to the Check Point Portal for centralized management.

Comparison of Active Directory and Microsoft ADFS

Identity and Trust supports Microsoft ADFS and legacy Active Directory. We recommend to use Microsoft ADFSActive Directory provides Identity and Trust with basic directory information about users and groups. Microsoft ADFS is software installed on your Active Directory server to allow it to function as a SAML server. SAML is the basis for modern authentication through a web browser using Single Sign-On.

 

Overview of the Directory Sync Domain Table:

The Directory Sync Domain table provides a detailed overview of domain synchronization settings. This table displays the associated domains, their sync status, and any configurations applied during the synchronization process. Use this table to manage and verify domain synchronization.

Note - In the Directory Sync, each row is a domain.

Configuring Directory Sync

How to Edit the Directory Sync Configuration

Warning -Clearing a previously selected domain removes all associated identities from the Check Point Portal within one hour.

To select or change the Active Directory that you want to synchronize with the Check Point Portal.

  1. Open the Identity Collector application and select Directory Sync.

  2. Select the edit icon.

  3. In the Add/Edit Servers window, select the applicable AD.

  4. Click OK.

Important - The Identity Collector must remain operational at all times to maintain an active connection. Failure to do so will result in the automatic deletion of identities within one month.