How to ignore username's NTLM or "down-level logon name" domain name prefix sent by a radius client or agent in RSA Authentication Manager 8.x
Originally Published: 2015-01-13
Last Modified: 2024-12-18
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Palo Alto / Radius client
Issue
The UPN Keywork RSAOMIT allows stripping off of NTLM names from in front of a UserID, so you are left with a SamAccountName
Resolution
- Go to Security Console > Settings > Agent Settings.
- In the section Domain Name Mapping, enter the domain name in the NTLM Name (for ex. COGSWELLCOGS).
- Enter RSAOMIT in the UPN Name. RSAOMIT is a keyword which will suppress only the NTLM Name specified. If you have more than one DOMAIN to omit, add additional mappings to RSAOMIT.
- Click Save to save changes.
COGWELLCOGS\userid will now authenticate as user id userid.
Related Articles
Microsoft’s Internet Information Server must be installed prior to starting the RSA Authentication Agent for Web for IIS i… 117Number of Views RSA SecurID Software Token Administrator's Guide 575Number of Views Change an Operations Console Administrator's Password 254Number of Views RSA MFA Agent 3.0 for Microsoft AD FS Administrator's Guide 473Number of Views Troubleshooting RSA MFA Agent for Microsoft AD FS 68Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?