> Source: [sk184640](https://support.checkpoint.com/results/sk/sk184640)

# sk184640 - Identity Awareness Gateway connected to multiple Entra ID tenants does not fetch access roles from any of the tenants, though there is an Entra ID problem with only some of the tenants

| Property | Value |
|----------|-------|
| Solution ID | sk184640 |
| Date Created | 2026-02-05 |
| Last Modified | 2026-02-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Multiple SAML Identity Provider objects for different Entra ID tenants exist on the same Identity Awareness Gateway. In Entra ID, at least one of the tenants is not functioning (for example: it has an invalid/expired application secret).  
  The Identity Awareness Gateway does not apply access roles for users in any of the Entra ID tenants.
* On the Identity Awareness Gateway, PDP debug logs (*$FWDIR/log/pdpd.elg* ) show messages similar to: `"MsGraphRestAPIGetUserAndGroupsQuery"` and `"No token"`.  
  `"Failed AzureAD lookup for user:"` and `"switching to LDAP"`.

## Cause

The expected behavior is for the Identity Awareness Gateway to fetch access roles from the functioning Entra ID tenants. Due to a Check Point issue, the Identity Awareness Gateway does not fetch access roles from any of the Entra ID tenants.

## Solution

To fix the non-functioning Entra ID tenant(s), an Entra ID administrator must resolve the issue in Entra ID.  

The Check Point issue was fixed. After you install the Check Point fix, the Security Gateway can fetch access roles from functioning Entra ID tenants, even if other Entra ID tenants are not functioning. The fix is included in:  

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) **starting from Take 44**
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) **starting from Take 119**
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) **starting from Take 183**

If you choose not to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:  

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:  
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
