> Source: [sk112374](https://support.checkpoint.com/results/sk/sk112374)

# sk112374 - "User is unauthorized" error message when user denied  access to Mobile Access portal 

| Property | Value |
|----------|-------|
| Solution ID | sk112374 |
| Date Created | 2016-07-18 |
| Last Modified | 2018-02-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * User trying to connect to the Mobile Access portal is denied with "User is unauthorized" message.
* The user is being authenticated by LDAP server. When the same user is defined in Mobile Access not as member of LDAP group, the authentication succeeds.

## Cause

The response received from the LDAP server for the user lookup request (sent from the Mobile Access Gateway) is missing the group membership portion.

The user cannot be matched againts the rule in the Mobile Access rule base that contains "LDAP group" in the source column.

Below is an example of such a partial response from the LDAP server:

*\[ 5881\]\[14 Jul 9:37:43\]\[CPLDAPCL\] Set Result From LDAP Message: fwset\<this = 0x8ad9328, count = 0\>*

*("CN=test.user,OU=users,OU=test.domain,DC=domian,DC=test,DC=com"*

*:type (user)*

*:fullname ("test.user")*

*:surname (test)*

*:givenName (vpn)*

*:displayName ("vpn test")*

*:name (vpn.test)*

*:userPrincipalName (vpn.test@test.test.domain.com)*

The missing portion is:

*\[ 5881\]\[14 Jul 9:38:06\]\[CPLDAPCL\] Member of: \<group the test.user belongs to\>*

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
