> Source: [sk180227](https://support.checkpoint.com/results/sk/sk180227)

# sk180227 - Lock/Unlock Screen does not generate Identity Awareness sessions

| Property | Value |
|----------|-------|
| Solution ID | sk180227 |
| Date Created | 2022-11-02 |
| Last Modified | 2024-11-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * In an environment with AD Query user authentication configured, end users cannot access the internet or internal resources.
* End users lock and unlock their endpoint Windows computers, but never log off.

## Cause

AD Query reads these events from the security event log on the Domain Controller so the Identity Awareness Gateway can generate a session:  

|--------------------------------|------------------------|
| Version of Domain Controller   | Event logs             |
| Windows Server 2003            | 672, 673, 674          |
| Windows Server 2008 and higher | 4624, 4769, 4768, 4770 |

<br />

When users log out and log in again, the Domain Controller generates the events shown above and forwards them to the Identity Awareness Gateway. The Identity Awareness Gateway then creates a session for the user and matches the user's Access Role.  

When the user locks and unlocks the endpoint Windows computer, the Domain Controller creates event log 4801 and event log 4624 type 7. AD query does not support these event logs, so it cannot generate a user session and cannot match the user's Access Role.  

For more information, see the [Identity Awareness Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=436) for the relevant version \> "Configuring Identity Sources" chapter \> "Configuring AD Query" section \> "Troubleshooting for AD Query" procedure \> Step 3

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
