> Source: [sk178409](https://support.checkpoint.com/results/sk/sk178409)

# sk178409 - Check Point Portal does not assign Admin or Read-only roles to users that connect with SSO

| Property | Value |
|----------|-------|
| Solution ID | sk178409 |
| Date Created | 2022-03-16 |
| Last Modified | 2026-05-11 |
| Technical Level | General |
| Products | Check Point Portal |
| Versions | Cloud |

## Symptoms

- Check Point Portal does not assign Admin or Read-only roles to users that connect with SSO.

## Cause

The User Group settings in the Check Point Portal do not contain the correct Microsoft Entra Group ID in the IDP ID field, which leads to incorrect group assignment for users authenticating through SSO.

## Solution

Follow these steps:

1. **In Azure**:

   1. In Microsoft Entra ID, add the Admin or Read-only groups to the list of users and groups. Then save their Group Object ID to be claimed.

   2. Set the Microsoft Entra Groups for the Admin or Read-only roles to use their object ID when claimed.  
      See the [Microsoft Entra ID Documentation](https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-group-claims) for more instructions on configuring group claims.

2. **In Check Point Portal**:

   * When configuring User Groups, set the IdP ID field to contain the group Object ID for the applicable group of the Admin or Read-only roles.

   For more information, refer to the [Check Point Portal Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Default.htm?cshid=ID022) and see **Preliminary Configuration of a User Group**.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
