Just-in-time synchronization failed - unable to contact directory server with RSA Cloud Authentication Service (CAS)
Originally Published: 2025-06-19
Article Number
Applies To
RSA Product Set: RSA ID Plus
RSA Product/Service Type: RSA Cloud Authentication Service
Version(s): All supported versions
Issue
Users fail to authenticate and the following error in the user event monitor:
Jut-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Unable to contact directory server.
Cause
The cause is the connection between the Cloud Administration Console and the Active Directory is failing. This could be caused by various reasons, but few of the most popular reasons are:
- The account used in the LDAP binding is expired, disabled, locked, or its password has been expired or changed.
- If you are using LDAPS, the SSL certificate might be the issue if it was expired or changed on the Active Directory.
- The identity router might be distressed or down.
- A network issue.
- A configuration issue.
In this article we will focus on fixing the binding account issue and the SSL certificate.
Resolution
To begin,
- Log in to your Cloud Administration Console.
- Go to User > Identity Sources.
- Click on Edit for the identity source that is having a problem.
- In the Identity Source Details section go down to:
- Directory servers:
- In the table that contains all the domain controllers listed for this Active Directory, edit each connection to change the binding account or its password.
- The edit button is a pencil shaped icon.
- SSL/TLS Certificates:
- If the certificate is missing, expired, or you just need to change it, you can change it in this section.
- Directory servers:
- After doing the needed changes keep clicking on Next Step then Save and Finish.
- Publish Changes to apply the changes that you made.
- Try to authenticate again or manually sync the users.
Notes
If that didn't help fixing you issue, please contact RSA Technical Support for assistance.
Related Articles
enVision: how to specify just one collector using lsdata 48Number of Views Unable to activate virtual host certificate; RSA Authentication Manager is unable to activate your selected certificate at… 117Number of Views RSA Community just got easier to navigate 30Number of Views Authentication Manager agent / server contact list and the sdconf.rec file 364Number of Views Unable to login to RSA Authentication Manager Security Console as super admin 5.29KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Adding a Palo Alto RADIUS dictionary to RSA RADIUS for RSA Authentication Manager 8.x
Don't see what you're looking for?