LDAPv3 User Verification for Cloud Access Service
LDAPv3 User Verification for Cloud Access Service
The identity router verifies the user’s identity source account by checking with the directory server. If the account is enabled, the identity router sends the Authenticate OTP to the Cloud Access Service (CAS) for verification. If your deployment uses an LDAPv3 identity source, RSA checks the following user attributes to determine the user's disabled status.
| Attribute | Setting |
|---|---|
| ds-pwp-account-disabled | true for disabled accounts. |
| nsaccountlock | true for disabled accounts. |
| shadowExpire | 0 for disabled accounts. |
If your LDAPv3 server does not use these attributes to indicate disabled status, RSA treats all users in the identity source as enabled.
Related Articles
Local Entitlement stays in pending verification state in RSA Governance & Lifecycle 106Number of Views Live Verification Policy 53Number of Views Change requests provisioned by AFX remain in "pending action" or "pending verification" in RSA Governance & Lifecycle 185Number of Views RSA Self Service module will not allow special characters in the username. 41Number of Views Live Verification for Users 80Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?