> Source: [sk183729](https://support.checkpoint.com/results/sk/sk183729)

# sk183729 - Threat Prevention policy installation fails when using Identity Tag objects in the Protected Scope column in the Global Domain

| Property | Value |
|----------|-------|
| Solution ID | sk183729 |
| Date Created | 2025-08-05 |
| Last Modified | 2025-08-11 |
| Technical Level | Advanced |
| Products | Security Gateway, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |
| Platform | Smart-1 |

## Symptoms

- * Policy installation fails on the Security Gateway when you use an Access Role (Identity Tag object) in the Protected Scope column of the Threat Prevention policy in the Global Domain.

* Debug logs show errors such as:
  ```````
  gen_amw_identity_roles_list amw_id_role_name=````: No such file or directory gen_amw_rulebase_tables: gen_amw_identity_roles_list failed amw_load: gen_amw_rulebase_tables failed

  <br />

  ```
  * SmartConsole displays this message: 
    "`Identity Awareness changes were detected in the Anti-Malware rule base. Access Policy installation is required.`"
    Unknown user group errors related to the Identity Tag object appear.

## Cause

There is a limitation in the `amw_loader` component of the Threat Prevention policy stack, when using Identity Tag objects in the Protected Scope column of the Threat Prevention policy in a Multi-Domain environment.  
The function `gen_amw_identity_roles_list` fails to retrieve the required object, resulting in policy installation failure.  
R\&D confirmed that Identity Tag objects are not supported by design in the Threat Prevention policy protected scope column.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
