> Source: [sk144532](https://support.checkpoint.com/results/sk/sk144532)

# sk144532 - Rule with Access Role is not matched

| Property | Value |
|----------|-------|
| Solution ID | sk144532 |
| Date Created | 2019-01-23 |
| Last Modified | 2019-01-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- In the Access Role, both UserID and MachineID are specified, but the proper rule which contains the Access Role is not matched/ enforced.

## Cause

The machine identity in Microsoft Windows is published only following up a reboot. This is by design.  
After the reboot, the machine identity is queried by the Security Gateway using the ADquery.  
This identity is expired after 12 hours, and it would require another authorization. At this time the machine identity is missing from the Security Gateway.  
When the Security Gateway request the identification again, it receive only the Username without the machine identity.  
As a result, the identity is kept in the Gateway's table only with the username, and with an empty machine ID. Thus, the rule with the access role is not matched.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
