> Source: [sk147417](https://support.checkpoint.com/results/sk/sk147417)

# sk147417 - Users are not authenticated when an identity source provides the login name in 'User Principal Name' format "user@domain"

| Property | Value |
|----------|-------|
| Solution ID | sk147417 |
| Date Created | 2019-02-25 |
| Last Modified | 2023-12-06 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- When an identity source provides the login name in the 'User Principal Name' format (as in, "user@domain"), and this identity source has a default login attribute defined (typically `sAMAccountName`), users encounter authentication issues, and they are unable to authenticate successfully.

## Cause

A 'User Principal Name' formatted name will not match the content of the login attribute `sAMAccountName` and vice versa.  
To keep the default login attribute definition and allow users to authenticate successfully, split the 'User Principal Name' (as in, username@domain) into the user name and domain based on the position of '@'.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 89
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 76
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 103
* [Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380) starting from Take 225

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

By default, if the PDP receives a 'User Principal Name' representation of the user name and domain (as in,` username@domain`), it would **NOT split** the username from the domain and the input remains as received.

The Hotfix above allows you to change the default behavior for the different identity sources and split the user name from the domain based on the '`@`' position.

As part of the procedure described below, the file: identity_awareness_custom_settings.Cis edited.  
By editing it, you can add/change various identity awareness configurations.

The file should be edited on the Security Management Server and is passed to the Gateway by a policy push.

As the procedure requires you to edit theidentity_awareness_custom_settings.C file, it is recommended to back up the original file to save any custom configurations.

**To change the default behavior for an identity source and split the user name for the domain:**

1. On the Security Management Server, edit the file $FWDIR/conf/identity_awareness_custom_settings.C by following this steps:
   1. Back up the following file: *$FWDIR/conf/identity_awareness_custom_settings.C* If the environment is a Multi-Domain Management Server, make sure that you are in the proper CMA:

      `# mdsenv <desired CMA>`
      `# mcd`
   2. Edit the file and add the following section: "**user_at_domain_client_types_to_split**".

<!-- -->

This section contains all the identity sources for which the customer can configure a split (vpn, ida-agent, radius etc.).

<!-- -->

By default, the split configuration is disabled for all identity sources, as there is a hash mark at the beginning of all the lines (as in, #identity-collector).

<!-- -->

To configure a split for an identity source, remove the hash mark at the beginning of the relevant line and save the file.

<!-- -->

For example:

<!-- -->

To make the input received in UPN format split when received from identity source radius according to the '@' position, the section "

**ser_at_domain_client_types_to_split**

" should change from the default configuration:

<br />

`[user_at_domain_client_types_to_split]`  
` #In this section you can add identity sources for which to split the user name and Domain according to the position of @`  
` #captive-portal`  
` #ida-agent`  
` #vpn`  
` #ad-query`  
` #multihost-agent`  
` `**#radius**   
`#ida-api`  
` #identity-collector`  
` [/user_at_domain_client_types_to_split]`

To the below configuration:

<br />

`[user_at_domain_client_types_to_split]`  
` #In this section you can add identity sources for which to split the user name and Domain according to the position of @`  
` #captive-portal`  
` #ida-agent`  
` #vpn`  
` #ad-query`  
` #multihost-agent`  
` `**radius**   
` #ida-api`  
` #identity-collector`  
` [/user_at_domain_client_types_to_split]`

<br />

2. Install the policy on the necessary Security Gateway/s.

<br />

**Notes:**

* Make sure that the change is received by the Gateway by verifying that the change also appears on the Gateway in the *$* `FWDIR/database/identity_awareness_custom_settings.C` file after policy installation
* The file's path on the Security Management is: `$FWDIR/conf/identity_awareness_custom_settings.C`
* The file's path on the Security Gateway is: `$FWDIR/database/identity_awareness_custom_settings.C`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
