> Source: [sk105494](https://support.checkpoint.com/results/sk/sk105494)

# sk105494 - Access Roles do not get automatically updated after moving users from OUs in Active Directory server

| Property | Value |
|----------|-------|
| Solution ID | sk105494 |
| Date Created | 2015-04-09 |
| Last Modified | 2026-04-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Access Role is not associated for some users after moving users to different OUs in the AD server.
* Re-adding users in access role will resolve the issue .

## Cause

The Access Role in SmartDashboard contains a different DN (Distinguished Name) for the user than the DN that the user has after the move of the user's OU.

**Example:**

The Access Role contains the DN that the user had when the user was first added to the Access Role.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105494/IA21504091200.png)

After the move of the user's OU, the access Role is not updated automatically. Searching the Account Unit shows the new DN of the user, but it must be changed manually in the Access Role.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105494/IA11504091154.png)

**This behavior is by design.** The Management server does not keep a constant connection with all Domain Controllers to receive an update to the OU of a user, regarding any user group change on the AD server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
