> Source: [sk179584](https://support.checkpoint.com/results/sk/sk179584)

# sk179584 - Security Gateway still allows users that were removed from the Desktop Policy to connect

| Property | Value |
|----------|-------|
| Solution ID | sk179584 |
| Date Created | 2022-06-21 |
| Last Modified | 2022-11-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- Security Gateway still allows users to connect in this scenario:

1. Administrator configures a rule with a user group in the Desktop Policy to allow specific users to connect.

2. Administrator installs the Access Control Policy and the Desktop Policy on the Security Gateway.

3. The Security Gateway enforces the Desktop Policy rule correctly - only the specified users can connect.

4. Administrator removes some users from the user group.

5. Administrator installs only the Desktop Policy.

6. The Security Gateway still allows the removed users to connect.

## Cause

The enforcement module of an endpoint client gets information about user groups in the Desktop Policy from the Security Gateway on which you installed the Desktop Policy.

The Security Gateway gets information about user groups only after you install the Access Control Policy.

Meaning, if you do not install the Access Control Policy, the Security Group cannot get the changes in the user groups.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
