> Source: [sk60501](https://support.checkpoint.com/results/sk/sk60501)

# sk60501 - Active Directory (AD) Query does not recognize Users

| Property | Value |
|----------|-------|
| Solution ID | sk60501 |
| Date Created | 2011-01-11 |
| Last Modified | 2020-11-12 |
| Technical Level | Advanced |

## Symptoms

- * AD Query does not recognize Users, although it is configured successfully.
* "No AD Query" error message is displayed in SmartView Tracker.

## Cause

1. AD Query correlates users to IP Addresses by reading security Event Logs from the domain controllers. By default, the necessary events are logged. If the audit configuration was changed and the necessary events are not logged, AD Query will not be able to correlate users to IP addresses. To verify this, look for the necessary events on the Security Event Log on the domain controllers. The necessary events are:

   * Windows 2003 servers: 672, 673, 674
   * Windows 2008 servers: 4624, 4768, 4769, 4770.
   * Windows 2012 servers: 4624\*, 4768\*, 4769\*, 4770\*

   \*4624: An account was successfully logged on.  
   \*4768: A Kerberos authentication ticket (TGT) was requested.  
   \*4769: A Kerberos service ticket was requested.  
   \*4770: A Kerberos service ticket was renewed.

   **Note**: see "Success Audit" logs for the above events. The AD server may be configured to only log failures.
2. There has been Windows Management Instrumentation (WMI) related changes on the Domain Controller that require the WMI service to be restarted.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
