> Source: [sk177611](https://support.checkpoint.com/results/sk/sk177611)

# sk177611 - AD users do not appear in OUs from AD scanner instance

| Property | Value |
|----------|-------|
| Solution ID | sk177611 |
| Date Created | 2022-01-27 |
| Last Modified | 2022-01-29 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Windows |
| Platform | Open Server |

## Symptoms

- * Organizational Scanner scans customer's AD environment, but users do not appear in their organizational unit when searching for them in our portal, while correctly appearing on their AD server.
* Users are seen on AD, but appear missing when searching for them in their OU from User/Computers in SmartEndpoint console, or the Infinity web portal.

## Cause

Customer might be changing the Primary Group ID of the users to something different from the default "Domain Users" Primary Group.  

ADUC (Active Directory Users and Computers) has built-in management tools that allow admins to customize privileges for their users through the use of Primary Groups (PrimaryGroupIDs).   

Traditionally, the PrimaryGroupID user attribute needs to match the RID (or relative identifier) of the group with which the user is associated. By default, all Active Directory users have a PrimaryGroupID of 513, which is associated with the Domain Users group. If this is changed, the user has different privilege levels within the AD Tree.  

Our Organizational scanner is not designed to handle customized Primary Groups, therefore this is NOT supported.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
