> Source: [sk180370](https://support.checkpoint.com/results/sk/sk180370)

# sk180370 - Threat Extraction does not process Active Directory Users/Groups

| Property | Value |
|----------|-------|
| Solution ID | sk180370 |
| Date Created | 2022-12-06 |
| Last Modified | 2022-12-14 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |
| Platform | 5000 |

## Symptoms

- * When an Active Directory user/group is set in the source or destination column of a Threat Prevention rule, Threat extraction is not triggered, and the traffic is handled by other blades.

* The MTAD debug does not show the lines: *dlpe_users_fetch_user_start*

## Cause

Incorrect values are set in the database. The Parameter `fwldap_UseLDAP` is set to: False.

## Solution

1. Open GuiDBedit (Usually found in: `C:\Program Files (x86)\CheckPoint\SmartConsole\R81.10\PROGRAM\GuiDBedit.exe`).
2. Navigate to the **Global Properties** table \> **Properties** \> select object **firewall_properties** .  

3. Find field name **fwldap_UseLDAP** \> set value to **true** .  

4. Save and install policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
