> Source: [sk111996](https://support.checkpoint.com/results/sk/sk111996)

# sk111996 - No candidates in access role user selection when working with Kerberos authentication against Microsoft AD

| Property | Value |
|----------|-------|
| Solution ID | sk111996 |
| Date Created | 2016-10-25 |
| Last Modified | 2019-12-03 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.x, R82.20 |

## Symptoms

- When configuring Kerberos authentication for user selection in access roles, no items are found.

## Cause

In order to use Kerberos authentication against the domain controller, some conditions has to be fulfilled. Failure causes can be:

* Microsoft AD domain controller is 2008 server and above.
* Relevant account unit is not configured to use Kerberos authentication for user selection in Access Roles.
* No LDAP and Kerberos communication between the management server and the domain controller.
* The domain controller doesn't have the KDC service.
* Management server and the domain controller clocks aren't synchronized.
* RootDSE doesn't contain the correct DNS hostname in the 'dNSHostName' attribute.
* No DNS server is configured on the management server. The domain controller DNS hostname must be resolvable from the management server.
* Wrong configurations like wrong server IP, wrong port, wrong credentials, expired credentials and so on.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
