> Source: [sk32479](https://support.checkpoint.com/results/sk/sk32479)

# sk32479 - Cannot import "Domain Users" group  with an LDAP Entity

| Property | Value |
|----------|-------|
| Solution ID | sk32479 |
| Date Created | 2007-01-16 |
| Last Modified | 2024-02-15 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- When creating a new LDAP Entity and importing groups, the membership of all groups are imported, except for the group "Domain Users".

## Cause

"Domain Users" is the default primary group for users in a domain.

The LDAP queries our gateway sends to the Active Directory server will not return the above group due to Microsoft's implementation of the Active Directory server.

## Solution

Due to Microsoft's Implementation of the Active Directory server not returning primary groups, there are multiple solutions that can be suggested by Microsoft (creating a new group for all users, changing the primary group, etc.).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
