> Source: [sk115776](https://support.checkpoint.com/results/sk/sk115776)

# sk115776 - Specific user is not identified by Identity Awareness

| Property | Value |
|----------|-------|
| Solution ID | sk115776 |
| Date Created | 2017-02-06 |
| Last Modified | 2025-10-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * A specific user is not being authenticated by Identity Awareness when using AD query.
* When multiple users attempt to log in to access the internal server, they may encounter an issue where the traffic is unexpectedly dropped by the cleanup rule, even if the users are members of the Active Directory group.
* Running the commands:`'#pdp monitor user [user-name]'` and `'#pdp monitor ip [ip-address]'` does not show any information about the user.
* In pdp debug ('`pdp debug set all all`'), there is the following log:  
  `[ADLOG_DB (NAC::IS::TD::Important)] ADLOG::AssociationDB::handleAssociation: the user: User-name@company.domain is a well known service account`.
* The command ` " # adlog a control srv_accounts show " ` returns:  
  `Suspected service accounts (logged in more than xx machines):
  name@company.domain` for ADQuery Deployments
* The command ` " # pdp idc service_accounts " ` shows similar output for Identity Collector Deployments.
* Successful Logon Event is seen for an unrecognized user for the correct username and IP: "An account was successfully logged on". - 4624

## Cause

This behavior is by design.  

The "Automatically exclude users which are logged into more than xx machines simultaneously" option is enabled in **Identity Awareness** \> **AD Query** - **Settings** \> **Advanced**.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
