> Source: [sk184272](https://support.checkpoint.com/results/sk/sk184272)

# sk184272 - Active Directory user lockout when enabling AD Query on Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk184272 |
| Date Created | 2025-11-09 |
| Last Modified | 2025-12-13 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- * After configuring AD Query as the Identity Awareness source on a centrally managed Quantum Spark gateway, the Active Directory user in the LDAP Account Unit is repeatedly locked out.

* Windows Event Viewer on the Domain Controller shows authentication failures and account lock events:

  *Event ID 4625 and 4776 with error code 0xc000006a.*
* SmartConsole Identity Awareness Device Status page shows "*Bad credentials*" error.

* The `'adlog a dc'` command returns connection error "*bad credentials or firewall blocks DCOM traffic \[ntstatus = 0xc0000022\]* ". However, the AD account has the required permissions as stated in [sk93938](https://support.checkpoint.com/results/sk/sk93938).

* The Domain Controller security policy is set to:

  Security Policy \> Security Settings \> Local Policies \> Security Options \> Network security: LAN Manager authentication level = "*Send NTLMv2 response only. Refuse LM \& NTLM*".
* The CLI command `'set user-awareness advanced-settings use-ntlmv2 true'` does not resolve the issue.

## Cause

The Quantum Spark Gateway sends authentication requests using NTLMv1 by default. The Domain Controller, configured to accept only NTLMv2, treats NTLMv1 requests as failed logins. After exceeding the lockout threshold, the AD account is locked.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
