> Source: [sk172003](https://support.checkpoint.com/results/sk/sk172003)

# sk172003 - Advanced Migration fails with "Scheme adjustment had failed" error

| Property | Value |
|----------|-------|
| Solution ID | sk172003 |
| Date Created | 2021-02-14 |
| Last Modified | 2021-06-27 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | Smart-1, Open Server |

## Symptoms

- * Advanced Migration fails with "`Scheme adjustment had failed`" error.
* `migrate-YYYY.MM.DD_HH.MM.SS.log` shows:  
  \[1 Feb 13:33:17\] \[CommandRunner::exec\] ERR: Command execution had failed  
  \[1 Feb 13:33:17\] ..\<-- CommandRunner::exec  
  **\[1 Feb 13:33:17\] \[SchemaChangesRunner::exec\] ERR: Scheme adjustment had failed**   
* `cpm_for_cpdb-DMMMYYYY-HHMMSS.elg` shows:  
  01/02/21 13:31:13,621 INFO coresvc.internal.ValidationsSvcImpl \[main\]: Added 17 Links: (took 206 millis)  
  01/02/21 13:31:13,622 INFO coresvc.internal.PermissionManagerSvcImpl \[main\]: finding osRole without threat_all_layers primitive  
  01/02/21 13:31:13,652 INFO coresvc.internal.PermissionManagerSvcImpl \[main\]: didn't find os role without threat_all_layers for osRole 79f5386d-c18a-4aa3-bd2e-6c56779650f7  
  01/02/21 13:31:13,652 INFO coresvc.internal.PermissionManagerSvcImpl \[main\]: updating folder accesses that links to osRoleGroup null to link osRoleGroup OsRoleGroup{objId=812c8da6-26ea -48d1-b0e1-86bd159faddf, name='Auto role - domain system role - 65d3179b-5663-42ab-9737-a100f121c19b', roles=\[OsRole{name='Auto role - domain system role - 65d3179b-5663-42ab-9737-a100f 121c19b', description='null', permissionPrimitives count=24, primitivesHashCode=478409560, permissionRoleId=65d3179b-5663-42ab-9737-a100f121c19b}\]}  
  01/02/21 13:31:13,652 ERROR internal.operation.OperationSvcImpl \[main\]: caught exception "null" from class java.lang.NullPointerException ...  
  01/02/21 13:31:13,660 ERROR management.default_database.FixGlobalVpnMgmtPermissionRolesForRWCustomSchemaChanges \[main\]: **error occurred while trying to update permission roles.** java.lang.NullPointerException at com.checkpoint.management.dleserver.coresvc.internal.PermissionManagerSvcImpl.createRoleGroupForDomainSystemFolder_aroundBody22(PermissionManagerSvcImpl.java:591) at com.checkpoint.management.dleserver.coresvc.internal.PermissionManagerSvcImpl$AjcClosure23.run(PermissionManagerSvcImpl.java:1) ...  
  01/02/21 13:31:13,664 ERROR cpm.commands.SchemaChangesCommand \[main\]: **Install of schema change com.checkpoint.management.default_database.FixGlobalVpnMgmtPermissionRolesForRWCustomSchemaChanges failed.**

  <br />

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 34
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 114
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 235
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 202

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
