Authentication to restricted agents with Active Directory users fail in Authentication Manager 8.1
Originally Published: 2016-06-15
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 or later
Issue
- Authentication to restricted agents with users in AD is failing with the following error:
Principal does not belong to any groups activated on restricted agent
- The system activity monitor shows a failure to read the identity source group:
- Granting access to some groups via Access > Authentication Agents > Manage Existing then selecting the Restricted tab then choose to Grant Access to More User Groups > select group(s) and get error as below:
There was a problem processing your request.
The identity source association of the user group <group_name> has changed. Run the Scheduled Identity Source cleanup job to update the User Group association. You must re-configure the group data related to Authentication Manager, for example access to restricted agents, restricted access times and notes.
- Test connections in Operations Console are all successful
- Running Clean Up Unresolvable Users or restarting services doesn't help.
Cause
Resolution
- In Security Console navigate to Setup > Identity Sources > Schedule Cleanup.
- Click the Schedule Cleanup checkbox and set the Run Time for the job.
- When done, click Save.
- Navigate to Administration > Batch Job to check that the batch job is complete.
- Select user groups to grant access to the restricted authentication agents. Select Access > Authentication Agents > Manage Existing.
- Click the Restricted tab and select Grant Access to More User Groups from the Action Menu.
- Search and select group(s) then click Grant Access to User Groups.
Related Articles
How to create an external identity source to Active Directory in RSA Authentication Manager 8.x 1.83KNumber of Views The Active Directory Account Collector does not collect the AD Domain Users Group in RSA Identity Governance & Lifecycle 221Number of Views How to verify that RSA Authentication Agent for Windows can perform challenge user lookups across different Active Directo… 452Number of Views RSA Authentication Agent 1.0.1 for Active Directory Federation Services (AD FS) sends domain\samAccountName instead of UPN… 71Number of Views RSA PAM Authentication Agent cannot challenge users in Active Directory groups 267Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA-2026-07: RSA Identity Router Security Update for Third-Party Component Vulnerabilities Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?