An administrator is troubleshooting an Identity Awareness deployment where AD Query fails to resolve user identities for workstations located in a newly added branch office subnet. The Security Gateway can successfully ping the Domain Controllers in the branch office. What is the most likely cause of this communication failure?
AD Query requires active RPC and SMB communication to query Windows Security Event logs remotely from Domain Controllers. When intermediate or host firewalls block these administrative ports, the gateway cannot read login events, causing identity resolution to fail completely.
Why this answer
AD Query relies on specific remote procedure call mechanisms and Windows Management Instrumentation protocols to read Security Event logs from Domain Controllers. If required ports like RPC Endpoint Mapper (135), SMB (445), or dynamic RPC ports are blocked by intermediate firewalls or host firewalls, the gateway cannot poll logs, resulting in complete identity resolution failure.
Exam trap
Engineers often assume that successful basic connectivity like pinging the Domain Controller means AD Query will function, overlooking that specific management and log-scraping ports might be blocked.