RSA Product/Service Type: Application Portal
When using Microsoft Integrated Windows Authentication (IWA) as an Identity Provider, the IWA server is typically only accessible by users on an enterprise's internal network. If IWA is configured to be used automatically this can prevent external users from being able to access the application portal.
Restricting Access to Automated SSO Agent IdPs Using Authentication Source Access Rules can be used to force external users to the portal login page.
However, the IWA icon will still be displayed on the portal which may cause confusion for end users.
This is functioning as designed for the default application portal. Possible workarounds include:
- Sending an end-user communication explaining that external users must log in with username/password.
- Changing the IWA icon (Users > Identity Providers > Edit > Portal Display) to something less visible or that somehow conveys to the end user not to use this option.
- Replacing the default portal with a custom portal as described in the RSA ID Plus IDR SSO Agent Custom Web Portal Developer's Guide and the article on how to Configure a Custom Portal Page for Web Applications.
RSA SecurID Access product improvement suggestions can be made by RSA customers on the RSA Ideas for the RSA SecurID Suite page in RSA Link.
Related Articles
Signature cryptographic validation not successful error for all RSA SecurID Access integrated Windows Authentication (IWA)… 128Number of Views Integrated Windows Authentication 28Number of Views Users cannot authenticiate to the RSA SecurID Access Portal or protected applications using Microsoft Integrated Windows A… 193Number of Views Deploying Integrated Windows Authentication 86Number of Views IWA Keyset does not exist 27Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process