> Source: [sk184073](https://support.checkpoint.com/results/sk/sk184073)

# sk184073 - Identity Collector service unable to add Domain

| Property | Value |
|----------|-------|
| Solution ID | sk184073 |
| Date Created | 2025-10-01 |
| Last Modified | 2025-10-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Error when attempting to add a domain in the Identity Collector: `Invalid Credentials / permissions; please check credentials and 'Event Log Readers' group membership.`
* The service account is a member of the Event Log Readers group
* The ia_ag.log from the Identity Collector shows: `DCEventQuery::SubscribeToEvents: general error Access is denied`.

## Cause

The issue occurs due to a misconfiguration in the Windows Security event log Access Control List (ACL) on the Domain Controller. The "Event Log Readers" group (Security Identifier \[SID\] S-1-5-32-573) was missing from the custom security descriptor (CustomSD) for the Security event log. As a result, the service account, although a member of the correct group, did not have the required permissions to subscribe to and read the Security event log remotely. This misconfiguration often results from custom Group Policy Objects (GPOs) or manual changes to event log permissions.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
