> Source: [sk147332](https://support.checkpoint.com/results/sk/sk147332)

# sk147332 - Unable to add new AD users to user access role after upgrade to R80.x

| Property | Value |
|----------|-------|
| Solution ID | sk147332 |
| Date Created | 2019-02-17 |
| Last Modified | 2022-11-15 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- When opening Access Roles object -\> Users tab -\> Specific users/groups and clicking "+", it shows "`Error retrieving results`"

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk147332/josef1902180737.png)

## Cause

The connection with the AD has been lost after the Fingerprints were changed on the DC but not on the LDAP Account Unit.  

- The procedure is:  

a) In Smart Console Navigate to the 'Servers' tab in the Object categories.  
b) Select the 'LDAP Account Units' and choose the required LDAP, right-click and choose 'Edit'.  
c) Navigate to the 'Servers' tab within the 'LDAP Account Unit'.   
d) Select the Server in question and choose 'Edit'. Then once in the 'LDAP Server Properties' click the 'Encryption' tab at the top and check the 'Use Encryption (SSL)' checkbox.  
e) Compare the current Fingerprints to the outputs of:  
# fwm fingerprint \<Domain_Controller_IP\> 636  

- When the AD changing the fingerprints the Management server can't fetch it automatically and manual fetching need to be done.  

<br />

<br />

<br />

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
