> Source: [sk179821](https://support.checkpoint.com/results/sk/sk179821)

# sk179821 - AD Query and Identity Logging do not work with Domain Controller on Windows Server 2022

| Property | Value |
|----------|-------|
| Solution ID | sk179821 |
| Date Created | 2022-08-17 |
| Last Modified | 2023-02-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * The traffic is not matched to Identity Awareness Access Roles as expected.

* SmartConsole logs from the Identity Awareness Gateway do not show User / Machine identities.

* Output of the "`adlog a dc`" command on the Identity Awareness Gateway shows:

  ```
  
  [Expert@IDA_GW:0]# adlog a dc
  Domain controllers:
  Domain Name              IP Address                Events (last hour)   Connection state
  ===========================================================================================================
  <Name of Domain>        <IP Address>               0                    connection had internal error [ntstatus = 0x80010111]
  
  Ignored domain controllers on this gateway:
  No ignored domain controllers found.
  [Expert@IDA_GW:0]#
  ```

* Output of the "`adlog l dc`" command on the Management Server shows:

  ```
  
  [Expert@MGMT:0]# adlog l dc
  Domain controllers:
  Domain Name              IP Address                Events (last hour)   Connection state
  ===========================================================================================================
  <Name of Domain>        <IP Address>               0                    bad credentials or firewall blocks DCOM traffic [ntstatus = 0xc0000022]
  
  Ignored domain controllers on this gateway:
  No ignored domain controllers found.
  [Expert@MGMT:0]#
  ```

* When configuring the Identity Awareness Software Blade for the first time and selecting AD Query in the Identity Awareness Configuration wizard, the connectivity test might fail with this error:

  ```
  
  User is not a domain administrator, as such AD Query will not work.
  Click back and chose another authentication method.
  ```

## Cause

Issue in Microsoft Windows Server 2022.

## Solution

### Procedure

Follow these steps to apply the Microsoft fix:

1. Download, install, and update your Windows server with one of these:

   * The **[Cumulative Update 10 January 2023---KB5022291 (OS Build 20348.1487) - Microsoft Support](https://support.microsoft.com/en-gb/topic/january-10-2023-kb5022291-os-build-20348-1487-38772acf-103f-463e-9d60-486174e806b2)**

   * A Cumulative Update (CU) released after that date.

2. Download the Known Issue Rollback (KIR) **[from here](https://download.microsoft.com/download/1/c/d/1cd64277-8c20-4a7e-9c54-569e3c0ba09e/Windows%20Server%202022%20KB5022291%20221215_03057%20Feature%20Preview.msi)** and install it.

   **Notes about the KIR**:
   * This KIR is necessary until the release of the CU scheduled for the second week of April 2023, which includes the fix without it being necessary to enable it with the KIR.

   * The KIR is necessary for all servers with one of these installed:

     * The CU mentioned above (dated 10 January 2023)
     * A CU released after that (examples: the **[CU dated 14 February 2023](https://support.microsoft.com/en-gb/topic/february-14-2023-kb5022842-os-build-20348-1547-be155955-29f7-47c4-855c-34bd43895940)** and the CU scheduled for the second week of March 2023).
3. After you install the KIR, you must enable it:

   1. On the Windows server, run this command:

      **gpedit.msc**
   2. In the **Local Group Policy Editor** window, go to **Computer Configuration** \> **Administrative Templates** \> **KB5022291 221215_03057 Feature Preview** \> **Windows Server 2022**.

      Example:

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk179821/Untitled1202302281812101.png)
   3. Open the **KB5022291 221215_03057 Feature Preview** setting.

   4. Select **Enabled** and click **OK**.

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk179821/Untitled2202302281812222.png)
4. Reboot the Windows server.

### Workarounds

These workarounds are also available:

* Use a lower Windows Server version.

* Work with **Identity Collector** instead of AD Query as an identity source.

  See the [Identity Awareness Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=436) for your version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
