> Source: [sk183787](https://support.checkpoint.com/results/sk/sk183787)

# sk183787 - New Azure AD roles fail to map in Smart-1 Cloud

| Property | Value |
|----------|-------|
| Solution ID | sk183787 |
| Date Created | 2025-09-08 |
| Last Modified | 2025-09-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |

## Symptoms

- * Newly created roles in Quantum Smart-1 Cloud for Microsoft Azure Active Directory (Azure AD) users are not mapped to users, either through groups or direct user objects. Existing roles and groups continue to function as expected.
* After login, the Identity Awareness log does not show the new group in the user's group list.
* Access Control List (ACL) rules referencing the new roles are not matched for affected users.
* Debug logs may show a similar to: `cloudid not found in DCS checkpoint AD`

* No matches for expected policy rules appear in logs for users assigned to new roles.
* After login, the expected role is not present and the relevant rule is not matched, as confirmed during internal testing.

## Cause

The Quantum Smart-1 Cloud Management Server did not contain the required configuration file:  
`$FWDIR/conf/install_manager.conf`  

This file is essential for mapping of Azure AD roles and groups to Check Point user objects during policy installation and Identity Awareness processing. Without it, changes made in Azure AD are not reflected in the Check Point management database. As a result, new roles are not mapped to users, and ACL rules are not matched.

The file may have been accidentally deleted or moved. A backup was available and restored.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
