Authentication to restricted agents with Active Directory users fail in Authentication Manager 8.1
Originally Published: 2016-06-15
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 or later
Issue
- Authentication to restricted agents with users in AD is failing with the following error:
Principal does not belong to any groups activated on restricted agent
- The system activity monitor shows a failure to read the identity source group:
- Granting access to some groups via Access > Authentication Agents > Manage Existing then selecting the Restricted tab then choose to Grant Access to More User Groups > select group(s) and get error as below:
There was a problem processing your request.
The identity source association of the user group <group_name> has changed. Run the Scheduled Identity Source cleanup job to update the User Group association. You must re-configure the group data related to Authentication Manager, for example access to restricted agents, restricted access times and notes.
- Test connections in Operations Console are all successful
- Running Clean Up Unresolvable Users or restarting services doesn't help.
Cause
Resolution
- In Security Console navigate to Setup > Identity Sources > Schedule Cleanup.
- Click the Schedule Cleanup checkbox and set the Run Time for the job.
- When done, click Save.
- Navigate to Administration > Batch Job to check that the batch job is complete.
- Select user groups to grant access to the restricted authentication agents. Select Access > Authentication Agents > Manage Existing.
- Click the Restricted tab and select Grant Access to More User Groups from the Action Menu.
- Search and select group(s) then click Grant Access to User Groups.
Related Articles
AAOP batch loader utility issue - Configuration problem - please check that the following parameter is configure: com.rsa.… 20Number of Views Unchallenged Active Directory users fail to authenticate with RSA Authentication Agent for PAM 284Number of Views Batch Jobs 31Number of Views RSA SecurID Authenticator 6.0 and 6.1 for Windows fails to import aCT-KIP URL 65Number of Views What is the maximum number of seeds in a batch RSA Security can ship on a floppy disk? 11Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio… Deploying RSA Authenticator 6.2.2 for Windows Using DISM Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?