> Source: [sk183449](https://support.checkpoint.com/results/sk/sk183449)

# sk183449 - Endpoint Domain Scanner for subdomains

| Property | Value |
|----------|-------|
| Solution ID | sk183449 |
| Date Created | 2025-05-09 |
| Last Modified | 2025-08-08 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |

## Symptoms

- * Groups and OUs are present in AD but do not appear in the Harmony Endpoint Administrator Portal.
* Machines/ users are present in AD but do not appear in the Harmony Endpoint Administrator Portal.

## Cause

If you have a forest with more than one domain, Active Directory Domain Services does not store all object data on a single domain controller --- for performance, scalability, and reliability reasons. A domain controller holds all information about only the domain that it is a member of (it has a full replica of the domain). But a domain controller does not hold complete information about any other domain.

## Solution

Scanning only the main domain is not enough. If a group is created in a child domain (for example, a1.com), and only the main domain (a.com) is scanned, the group will not appear in the Harmony Endpoint Administrator Portal.   

Each Active Directory domain contains only its own objects, and data is not automatically shared across domains - even within the same forest. For more information, see [Microsoft Documentation](https://learn.microsoft.com/en-us/windows/win32/ad/searching-domain-contents).  

Therefore, to retrieve machines / users or groups from child domains, each domain must be scanned individually.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
