> Source: [sk63943](https://support.checkpoint.com/results/sk/sk63943)

# sk63943 - In Identity Awareness, users are successfully identified, but their groups and access roles are not correctly identified or enforced

| Property | Value |
|----------|-------|
| Solution ID | sk63943 |
| Date Created | 2011-06-27 |
| Last Modified | 2023-03-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * In Identity Awareness, users are successfully identified, but their groups and access roles are not correctly identified or enforced.
* Output of "`pdp monitor user `*UserName*" command on Security Gateway shows that the user has been recognized, but there is no access role associated with this user.

## Cause

In SmartDashboard, two Account Unit (AU) objects were configured with the same Domain.

When two different LDAP Account Units are configured with the same Domain,  
access roles that are matched to groups from a specific Account Unit might not  
be matched following an LDAP fetch request for the other Account Unit.

When an access role is created, the user picker is tied to an Account Unit -  
users picked must match the DN ***and*** the Account Unit.  
If user exists in both Account Units, even with the same DN and the same servers on the back end -  
the access roles that have to be checked are loaded differently, depending from which AU / realm  
user is coming. The needed access role will not be checked unless the correct AU is queried.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
