> Source: [sk130112](https://support.checkpoint.com/results/sk/sk130112)

# sk130112 - "Some of the selected policies have been deleted from the Domain. Please remove them from the Advanced Policy Assignment Properties." error

| Property | Value |
|----------|-------|
| Solution ID | sk130112 |
| Date Created | 2018-06-24 |
| Last Modified | 2024-05-24 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server |
| Versions | R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- Reassignment of Global policy to CMA/Domain after removing a policy from it fails with error:

```

"Global Domain Assignment Failed: 
Some of the selected policies have been deleted from the Domain.  
Please remove them from the Advanced Policy Assignment Properties."
```

## Cause

In this specific scenario, the policy was deleted and published. Global policy was not updated when policy is removed from CMA/Domain.

## Solution

In this scenario, in MDS SmartConsole -\> "Advanced Access Control Assignment Settings" under Assignment, has the correct Domain policy name as well as a second Domain policy named "Unavailable".

### **Procedure:**

1. From MDS SmartConsole open the Global Assignment view.  

2. Right-click the Domain that has the General Policy reassignment problem.  

3. Select "Edit..."  

4. Verify Domains and Access Control information.  

5. Go to 'Advanced' under "Access Control".  

6. Verify the Domain policy name(s) under 'Name' and if we have 'Unavailable' domain policy name, select or highlight 'Unavailable' domain policy name and delete/'X' it.  

7. Publish and reassign Global Policy.

**Note:** Should the error persist, check the Treat Prevention policy for step 5 and continue the procedure.  

<br />

**If Policy from error not visible:**   
In this scenario with an error who's policy is not visible under "Advanced" for Access Control and/or Threat Prevention, *and who's Domain only contains policies that should receive the global assignment* , a change of config from "Specific" to "All" policies can be made. Then once the Global assignment succeeds in this config, a change back to "Specific" should result in successful Global assignment having now allowed the database to clear out the lingering associations between the deleted policies and the Global Assignment.   

**Procedure:**   

1. From MDS SmartConsole open the Global Assignment view.
2. Right-click the Domain that has the General Policy reassignment problem.
3. Select "Edit..."
4. Verify Domains and Access Control/Threat Prevention information.
5. Go to 'Advanced' under "Access Control" and/or "Threat Prevention".
6. Verify the Domain policy name(s) under 'Name' and if we do not see the policy names from the error, check the list of policies from the "+" list and verify all remaining policies are meant to receive the Global Assignment in this Domain. Once confirmed, change checked setting from "specific" to "all" policies.
7. Publish and reassign Global Policy.
8. Upon successful reassignment return to step 5 and revert the checked settings, re-add the policy(ies) then publish and reassign.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
