> Source: [sk164914](https://support.checkpoint.com/results/sk/sk164914)

# sk164914 - No Group Membership when user is authenticated by Identity Agent using Kerberos Authentication

| Property | Value |
|----------|-------|
| Solution ID | sk164914 |
| Date Created | 2020-02-04 |
| Last Modified | 2022-01-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * No Group Membership when user is authenticated by Identity Agent using Kerberos Authentication.

* When the user is receieved from other Identity Resources (such as AD Query), the group membership is fetched.

* In PDP debug ("pdp debug set all all") following logs are seen:  

  `

  [PID]@GW[DATE TIME] [KERBEROS_SERVER(KerberosLogger_Events)] bool KerberosAuthorizator::Init(gss_name_t): Failed to fetch krb logon-info`  
  `
  .`  
  `
  [PID]@GW[DATE TIME] [KERBEROS_SERVER(KerberosLogger_Important)] KerberosAuthorizator::KerberosAuthorizator(gss_name_t): Kerberos Authorization data processing failed`

## Cause

There are multiple LDAP Account Units for the same domain. The Security Gateway is unable to fetch the schema from the LDAP Account Unit to perform Kerberos Authentication.  
The way that LDAP Account Unit works is that each domain should have exactly one LDAP Account Unit, as there is mapping of domain name to Account Units.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
