How to Merge Users from Internal Database to an Existing Identity Source (Active Directory)
2 years ago
Originally Published: 2022-01-10
Article Number
000064983
Applies To
RSA Product Set: RSA SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform: null
Platform (Other): null
O/S Version: null
Product Name: null
Product Description: null
Issue
Having users saved in the internal database, and users are assigned tokens.
Need to use Active Directory without losing the token assignment.
Tasks
  1. Make sure that the active directory has the same exact users as the internal database.
  2. Download Encryption Key.
  3. Export Tokens and users.
  4. Upload Encryption file.
  5. Import tokens.
Resolution
  1. Open the Primary Security Console ----> Administration ---> Export/Import Tokens and users ---> Download Encryption Key ---> click "Download Now".
  2. Navigate to Administration >> Export/Import Tokens and users >> Export
    Tokens and users
    .
  3. Upload the Encryption File downloaded in step 1.
  4. Check the “Users with Tokens” option.User-added image
NOTE:  In case of having more than one subdomain, you will have to
export/import each sub domain individually.
5. Please choose the subdomain (if any, and choose System Domain if it is
the only present domain) you will be exporting.
  • Check the “Include subdomains” option
  • Check the “Export all users with tokens in domain”
User-added image
6. Wait for the Export Job to be done, then click on “Download File”.
  • User count and token count should be equal to the number of users and the number of tokens exported.
User-added image

7. After downloading the file, Navigate to Identity ---> Users ---> Manage Existing.
  • Note that if you have more than one sub-domain you will need to choose the sub-domains individually.
8. Delete the users from the Security Domain (each subdomain if needed).

9.To make sure that the importing procedure has been done correctly, navigate to Reporting ---> Real-time Activity Monitors ---> Administration Activity Monitor and click "Start Monitor".

10. Navigate to Administration ---> Export / Import Tokens and Users >> Import Tokens and Users.
Choose the file you have downloaded in Step 6, and then press Next.
  • Choose the subdomain desired (Or System Domain if no sub-domains).
User-added image

11. Map the Internal Database to your Active Directory.
User-added image

User-added image

Note that you will have to repeat the process for each subdomain if you are having multiple sub-domains, in order to migrate the whole users.

 
Notes
  • Make sure that users in the Active Directory are exactly the same users that are in the Internal Database
  • Make sure that all users have tokens assigned to them. Users with no tokens will not be included in the importing/exporting procedure.