RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
O/S Version: SUSE
- Change token policies on a subset of users
- Change policies to users in phases
Changing a policy assigned to a Security Domain changes the policy for all users in the Domain. It is not possible to change a policy for a subset of users in a Security Domain. However, it is possible to effectively change a policy on a subset of users by moving those users to a new Security Domain with the changed policy.
If a policy is assigned to more than one Security Domain and you want to change the policy for only one of the Security Domains, duplicate the existing policy. Then make the necessary changes to the duplicate policy, and assign it to the Security Domain you want to change.
- Open the Security Console and go to Administration > Security Domains > Manage Existing.
- The existing Security Domains are listed and each can be viewed to show the currently assigned policies.
- Go to Authentication > Policies >Token Policies > Manage Existing.
- Edit the policy to which you want to make a change.
- Click Save when done.
- Apply the token policy to a security domain.
If the policy is assigned to several Security Domains and you want to make a change to the policy for only some of the Security Domains,
- Go to Authentication > Policies >Token Policies > Manage Existing.
- Click on the policy and select Duplicate.
- Select the desired options on the duplicate policy and click Save.
- The policy can now be assigned to the Security Domains to which you want to make changes.
- Open the Security Console and go to Identity > Users > Manage Existing.
- Search for users, using the filters to select the subset of users you want to move.
- Check the box next to the users you want to move, and use the pull-down at the top of the screen to select Move to Security Domain....
- Click Go.
- On the next screen, select the new Security Domain.
- Click Move.
IMPORTANT: Administrators who are scoped to only have access to the previous Security Domain will not have access to the new Security Domain.
Related Articles
Customize login text for an RSA Authentication Agent for Web: IIS protected webpage 75Number of Views Risk-Based Authentication from Cisco ASA 9.3.1 redirects to wrong URL for RSA Authentication Manager 8.1 185Number of Views Risk-Based Authentication 24Number of Views How to change RSA SecurID token policies to require 6-character or 8 character PINs 209Number of Views There was a problem processing your request error when trying to edit Date and Time Settings on RSA Authentication Manager… 186Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio… Deploying RSA Authenticator 6.2.2 for Windows Using DISM