To eleborate a bit more:
Check Point currently does not allow grouping of access role objects.
If you need some kind grouping with Identity Awareness, this are your options:
- put multiple users in one access role (group changes have to be done on Check Point side)
- put one or multiple AD groups in one access role (group changes have to be done on AD side)
- a combination of the two points above
- use Identity Awareness API to assign members to access roles (group changes have to be done be the external system calling the API)