> Source: [sk84621](https://support.checkpoint.com/results/sk/sk84621)

# sk84621 - How to delete a scanned Active Directory sub-tree or a Domain from an organization tree on Endpoint Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk84621 |
| Date Created | 2012-09-12 |
| Last Modified | 2023-12-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| Platform | Smart-1 |

## Solution

It is possible to delete an Active Directory sub-tree that was scanned by mistake, or one of the scanned Domains that is no longer in use on Endpoint Security Management Server.

**Before removing nodes, check the possible impact:**

All nodes, except devices with installed 'DA' and users with 'ME' keys, will be deleted. The remaining nodes will be moved under "`Deleted users\computers`" folder with directly assigned data only. Nodes without direct assignments will inherit them from "`Deleted users\computers`" folder.

*Example*: If an administrator was defined as authenticated authority with possibility to login to all computers belonging to some OU, and after that this OU's hierarchy was deleted, the administrator will be deleted as well, which will prevent access on encrypted computers, even if they are still in Endpoint Security Server database.

**Recommended action plan before deletion:**

1. Discover all managed devices (marked by lock in User Interface) that belong to an OU that is planned for deletion.
2. Reset devices that will not be managed (right-click on a device node and choose "`Reset computer data`".
3. Copy rules, and assign them directly to the managed devices.
4. Assign authorized preboot users to the managed devices.

**To enable this feature:**

1. Close SmartEndpoint GUI.
2. Go to SmartConsole directory (e.g., `C:\Program Files (x86)\CheckPoint\SmartConsole\E80.40\PROGRAM\`).
3. Open **`EndpointManager.exe.config`** file in an plain text editor (e.g., Windows Notepad, Notepad++, UltraEdit)
4. Find the line **`<add key="SupportOUDeletion" value="False">`** , and change the value to "**`True`**".
5. Save all changes, and exit the editor.
6. Connect with SmartEndoint GUI to Endpoint Security Management Server again.

The nodes can be removed either via the "`Directory Scanner Configuration`" dialog ("`Tools`" -\> "`Directory Scanner`", choose the instance and press "`Remove`"), or via organization tree (choose a root node, right-click, choose "`Delete OU Hierarchy`").

**Note:**

* Check Point strongly recommends disabling this feature at the end of the deletion operation.

**Known Limitation:**   

Removal of large hierarchy that takes more than 5 minutes will lead to timeout in User Interface. The operation will continue in the background until completion.

**Related solution:** [sk104543 - After removing Active Directory sub-tree or a Domain from an organization tree, the removed Domain remains in WebRH "Domain" drop down menu](http://supportcontent.checkpoint.com/solutions?id=sk104543).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
