> Source: [sk184717](https://support.checkpoint.com/results/sk/sk184717)

# sk184717 - Identity Awareness Gateway does not match Microsoft Entra ID local users to access roles when R82 Management manages R81.x Gateways

| Property | Value |
|----------|-------|
| Solution ID | sk184717 |
| Date Created | 2026-02-23 |
| Last Modified | 2026-02-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Users authenticate successfully using Microsoft Entra ID (formerly Azure AD). However, the Policy Decision Point (PDP) Identity Awareness Gateway does not match these users to access roles based on Entra ID.
* The PDP successfully matches Entra ID users to access roles if the users originate in an external Entra ID tenant. The Entra ID names for these users start with "*EXT_ID_*".
* The version of the Management Server is R82. The version of the affected Security Gateway(s) is R81, R81.10, or R81.20.
* If the users use Remote Access VPN, the solution procedures in [sk179788](https://support.checkpoint.com/results/sk/sk179788) and [sk183250](https://support.checkpoint.com/results/sk/sk183250) do not resolve the issue.

## Cause

The Management Server receives the identity information from Entra ID, but does not forward this information to the PDP Gateways.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R82](https://support.checkpoint.com/results/sk/sk181127) Security Gateways

To fix the problem, upgrade the Security Gateways to version R82 or higher.  

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
