> Source: [sk182750](https://support.checkpoint.com/results/sk/sk182750)

# sk182750 - Duplicate user objects are created on server when user is acquired by Full Disk Encryption in hybrid Entra ID and joined Entra ID environments

| Property | Value |
|----------|-------|
| Solution ID | sk182750 |
| Date Created | 2024-10-14 |
| Last Modified | 2025-03-17 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E88.X |
| OS | Windows |

## Symptoms

- * Duplicate user objects for an Entra ID (formerly Azure AD) user are seen on the server after user has been acquired by Full Disk Encryption. Hybrid Entra ID users will be treated as Entra ID users by the client and will also be affected by duplicate user objects.
* Hybrid users will have their domain name set to AzureAD instead of the correct Active Directory domain name. The domain name AzureAD is seen in the user details on the server and during authenticating in pre-boot with the user on the client.
* User acquisition fails for a hybrid Entra ID user if Strong Authentication is enabled.
* Policy assignment might appear to be incorrect for the user. With duplicate user objects there is a risk for using incorrect user object. For example, during assigning policies and authorizing the pre-boot users.
* User data in Asset Management is not updated. If duplicate user objects exist for a user, user updates will only be reflected on the user object that has received the update.

## Cause

An issue on the client starting with E88.00 will use the domain name AzureAD for hybrid Entra ID users when acquired by FDE on the client instead of the correct Active Directory domain name. The server will then treat the acquired user as a new Entra ID user and create a new user object.   

The issue only occurs when a user is acquired from the client. Usually, user is acquired at first login to Windows when performing a fresh installation. Affected client versions for issues with hybrid Entra ID users are E88.0x, E88.1x, E88.2x, E88.3x and E88.4x.

## Solution

This problem was fixed. The fix is included starting from:

* [Endpoint Security Client E88.50](https://support.checkpoint.com/results/sk/sk182372)

<br />

If you choose not to upgrade, the Security Management Server must be updated with a fix for the duplication issue and the already created duplicates must be handled. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
