> Source: [sk62246](https://support.checkpoint.com/results/sk/sk62246)

# sk62246 - Directory Scanner scans objects out of search base

| Property | Value |
|----------|-------|
| Solution ID | sk62246 |
| Date Created | 2011-04-21 |
| Last Modified | 2024-10-24 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- User defines a search base of a specific OU (instead of the entire domain).The scanner scans objects that are not under the defined search base.

## Cause

The reason for that might be that under the defined search base there are AD groups that have members from outside that search base. Therefore the scanner tries to scan those members as well including their ancestors.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
