> Source: [sk115474](https://support.checkpoint.com/results/sk/sk115474)

# sk115474 - Some users are not getting associated with the PDP

| Property | Value |
|----------|-------|
| Solution ID | sk115474 |
| Date Created | 2017-01-16 |
| Last Modified | 2017-09-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When running the "`pdp monitor user <problematic username>`" command, only machine association or no association at all can be seen.  

* The pdp debug shows:   
  `[ADLOG_DB (NAC::IS::TD::Events)] ADLOG::AssociationDB::handleAssociation: no machine name in the association, the association disregarded`

## Cause

In the ADQuery configuration of "Identity Awareness" -\> "Active Directory Query" settings -\> "Automatically exclude users which are logged into more then" we have a limit of how many machines a user can be logged on before getting exclude, this option is enabled by default.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1484129319372/11111701110219.JPG)

<br />

When a user exceeds the limit, this user is excluded.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
