RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
A user with two separate accounts in an external identity source (for example, a standard Active Directory user account and a second AD admin account) may be unable to authenticate using the account that does not have a SecurID token assigned.
When authenticating via native SecurID protocol, one or more of the following errors appear in the Authentication Activity Monitor:
Principal does not possess one or more authenticators
No aliases found, unable to resolve principal by alias
Unable to resolve principal by login ID and/or alias
Unable to resolve login by user id and/or alias, or authenticator not assigned to user
This user ID is already in use by an unresolvable user in this realm
When authenticating via RADIUS, no error may appear in the Authentication Activity Monitor or authentication reports. Instead, check the RADIUS log file on the Authentication Manager primary instance:
/opt/rsa/am/radius/<date>.log
The log may contain a generic entry such as:
Unable to find user <user_ID> with matching passwordWhen a user has two accounts in the same external identity source, Authentication Manager may resolve the account with no token assigned instead of the account with the token, causing authentication to fail.
Authentication Manager searches the identity source to resolve the user's login. When two accounts share the same identity source, the system may match the unregistered account — one that has never had a token assigned — before it finds the registered account with the valid token. This commonly occurs when a user has a standard account (e.g., a regular user account) and a privileged account (e.g., an AD admin account) and only one has a SecurID token assigned.
For RADIUS clients, the same resolution failure occurs but produces no visible error in the Authentication Activity Monitor — the failure is only logged in the RADIUS log file.
In the following example,
- There is an Authentication Manager user named Jay Guillette.
- Jay's user ID of jguillette exists in the external identity source named IS1 and has a token assigned to him.
- Jay's user ID of AdminGuill exists in external identity source named IS2 and does not have a token assigned. This account must be unregistered in Authentication Manager, which means it has never had token assigned to it. See article here for solutions.
- Jay wants to be able to use the same token whether he authenticates as jguillette or as AdminGuill.
Prerequisite
If no user groups exist, first create an internal group or use an external LDAP group. From the Security Console select Identity > User Groups > Add New. Now add both the jguillette and AdminGuill user IDs to this group.
You will need to have a user group to assign to the user before continuing If authentication is through a RADIUS client, also create a RADIUS profile.
- Login to the Security Console.
- Navigate to Identity > Users > Manage Existing.
- Set the Search Criteria for Identity Source to IS1 where User ID contains jguillette.
- In the User ID column, click on Jay's user ID and from the menu choose Authentication Settings.
- In the Authentication Settings section,
- For the option of User Authenticates With, select Default User ID, or any of the following aliases.
- Select a user group from the list.
- In the User ID field, add the logon alias of AdminGuill.
- If authenticating with RADIUS, be sure to add a RADIUS profile value.
- Click Add.
- Click Save when done.
- Go back to Identity > Users > Manage Existing.
- Set the Search Criteria for Identity Source to IS2 where User ID contains AdminGuill
- In the User ID column, click on Jay's user ID and from the menu choose Authentication Settings.
- In the Authentication Settings section,
- For the option of User Authenticates With, select Only the following aliases. See screenshot below
- Select a user group from the list.
- In the User ID field, add the logon alias for jguillette, e.g. AdminGuill.
- If authenticating with RADIUS, be sure to add a RADIUS profile value.
- Click Add.
- Click Save.
- Navigate to Access > Authentication Agents > Manage Existing.
- Depending on the agent, click the Restricted or Unrestricted tab.
- Use the search fields to find the agent to which you want to enable logon aliases.
- Select the checkbox next to the agent to which you want to enable logon aliases.
- Do one of the following:
- For restricted agents, select Grant Access to User Groups from the Action Menu and click Go.
- For unrestricted agents, select Enable Logon Aliases from the Action Menu and click Go.
- Use the search fields to find the user groups to which you want to enable logon aliases.
- Select the checkbox next to the user group to which you want to enable logon aliases.
- Do one of the following:
- For restricted agents, click Grant Access to User Groups.
- For unrestricted agents, select Enable Logon Aliases with User Groups.
- Test authentication as both jguillette and as AdminGuill using the same token.
Verify:
Test authentication using both <primary_userID> and <secondary_userID> with the same token.
CAUTION: Wait for the tokencode to roll to the next value before testing the second user ID. Reusing the same tokencode within the same tokencode window will trigger a passcode reuse error in the Authentication Activity Monitor.
Confirm that both user IDs authenticate successfully against the protected agent.
RSA strongly recommends that you do not allow users to share the same token. It is a poor security practice as it negates non-repudiation.
Allowing the same person with two different Windows Accounts to use the same token with either account does not negate non-repudiation and therefore that use case is legitimate and the reason this article was written.In order to do this, you must make Authentication Manager believe there is only one account (with an alias) it, therefore, goes without saying that the Authentication Manager feature of Windows Password Integration will be unaware that there are two accounts, and will only maintain a single Windows password for both if you enable Windows Password Integration. You will either need to disable this feature for this user or have the user manually maintain the same password in AD for both accounts.
Related Articles
Duplicate User ID error when running All Users report in RSA Authentication Manager 8.x 1.72KNumber of Views Cannot add or manage a user with user ID <UserID>. User IDs must be unique within a deployment. This user ID is already in… 2.07KNumber of Views Assign a replacement RSA SecurID token to a user in RSA Authentication Manager 895Number of Views RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.22KNumber of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.14KNumber of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process