- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello..
I have configured identity awareness for AD query for one of the customer and everything working fine ,but recently we observe that if AD administrator changing any user from one OU(organization unit) to other OU than in checkpoint access rule its not getting updated its shows two detail for same user, so users are not getting access as per given rule.
Kindly let me know how to update OU automatically.
Hi Soni,
I assume from your scenario you are using access roles and then adding the users from AD into the access roles? Which in turn you are using in your rules.
If so I believe that the user is referenced by its DN within the access role.
So based on this you would need to modify the access role with the account once it's been moved.
One way around this would be to use AD groups and then add the users to the AD groups, then use the group within the access role. It would still be susceptible to the same issue of moving groups, but I assume that activity would be far less than moving users.
If I am way off with the above, if you could provide further information on your setup please?
Regards
Mark
Hi Mark,
Thanks for update.
My concern is below .
For Ex:One user say name as "A" in "XYZ" OU so while creating access rule for user 'A' it will be with OU 'XYZ' and suppose user'A' is changing to different profile than AD administrator will change user 'A' OU ,so in this case we are facing the issue because in dashboard access rule it was with old OU and its not getting automatically update in access rule and Administrator is not ready to give the information of changing the OU.
So please tell me know how to come out from this issue .
For reference I am adding the screenshot.

In above screenshot,Rao user was in HO_user OU ,but due to some reason AD administrator changed his OU than he was not getting access which he has before.so after doing lots of research I found OU has changed ,than I created a new access rule for same user than he started getting the access.
Regards,
Soni
Hi Soni,
Because the DN from within the access role cannot be updated automatically. When selecting the user for your access role, the system uses the DN to determine the account to use within the access role. To get around what you are seeing I believe you have 2 options going forward.:
Hope this helps.
Regards
Mark
Hello, I strongly recommend you changed your access rule to use AD groups...
Hi,
Can you please let me know where to make a group on AD or on Checkpoint ,In AD we cant do any changes .
In CP you just have to create the AR object and use the group which has been defined in the AD, similar to single users.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 18 | |
| 10 | |
| 9 | |
| 9 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY