Authentication to restricted agents with Active Directory users fail in Authentication Manager 8.1
Originally Published: 2016-06-15
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 or later
Issue
- Authentication to restricted agents with users in AD is failing with the following error:
Principal does not belong to any groups activated on restricted agent
- The system activity monitor shows a failure to read the identity source group:
- Granting access to some groups via Access > Authentication Agents > Manage Existing then selecting the Restricted tab then choose to Grant Access to More User Groups > select group(s) and get error as below:
There was a problem processing your request.
The identity source association of the user group <group_name> has changed. Run the Scheduled Identity Source cleanup job to update the User Group association. You must re-configure the group data related to Authentication Manager, for example access to restricted agents, restricted access times and notes.
- Test connections in Operations Console are all successful
- Running Clean Up Unresolvable Users or restarting services doesn't help.
Cause
Resolution
- In Security Console navigate to Setup > Identity Sources > Schedule Cleanup.
- Click the Schedule Cleanup checkbox and set the Run Time for the job.
- When done, click Save.
- Navigate to Administration > Batch Job to check that the batch job is complete.
- Select user groups to grant access to the restricted authentication agents. Select Access > Authentication Agents > Manage Existing.
- Click the Restricted tab and select Grant Access to More User Groups from the Action Menu.
- Search and select group(s) then click Grant Access to User Groups.
Related Articles
The Active Directory Account Collector does not collect the AD Domain Users Group in RSA Identity Governance & Lifecycle 222Number of Views Unchallenged Active Directory users fail to authenticate with RSA Authentication Agent for PAM 303Number of Views How to create an external identity source to Active Directory in RSA Authentication Manager 8.x 1.85KNumber of Views When Active Directory is integrated using Winbind, group membership for Active Directory users fails with the RSA Authenti… 168Number of Views RSA Authentication Agent 1.0.1 for Active Directory Federation Services (AD FS) sends domain\samAccountName instead of UPN… 75Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?