> Source: [sk114426](https://support.checkpoint.com/results/sk/sk114426)

# sk114426 - Users access to resources allowed in rule with 'Access Role' fails

| Property | Value |
|----------|-------|
| Solution ID | sk114426 |
| Date Created | 2016-11-10 |
| Last Modified | 2021-11-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Users cannot access resources which they should have access to by rules with 'Access Roles'.
* Running the command `#'pdp monitor user <username>'` on the Security Gateway, does not show the appropriate access role even though it is configured in SmartDashboard.

## Cause

In SmartDashboard there are two account units for the same domain, and the access role is second to the "secondary" account unit.

When an 'Access Role' is set to the "secondary" account unit, the role will not correlate to the correct users/groups due to the conflict of having two account units for the same domain.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
