RSA Authentication Agent 1.0.1 for Active Directory Federation Services (AD FS) sends domain\samAccountName instead of UPN to Authentication Manager
Originally Published: 2017-04-28
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Active Directory Federation Services (AD FS)
RSA Version/Condition: 1.0.1
Issue
- At the AD FS front end web page the customer enters their UPN such as jon.smith@company.com in the User Name field, along with their password.
- But ADFS prompts for a passcode with samAccountName, prefixed with the domain; for example, company\jon.smith instead.
- Since the user ID is in UPN format in Authentication Manager, the Domain\samAccountname format of the same user is not found, so logon fails with failure to resolve User ID or Alias.
Cause
The SecurIDAuthProvider(MicrosoftIdentityServer...).log for the AD FS agent will show the claim type, in this case windowsaccountname, when it should be UPN.
Resolution
- The ADFSUnregisterationSample PowerShell script should be in C:\Program Files\RSA\RSA Authentication Agent\AD FS Adapter\SampleRegistrationScripts.
- In PowerShell change directory to the ..\AD FS Adapter\SampleRegistrationScripts directory and run the ADFSUnregistrationSample.ps1 (or your customized) PowerShell script
- Follow this by running the ADFSRegistrationSample.ps1 (or your customized) PowerShell script
- If AD FS is running in a farm of AD FS servers, the (un)registration commands are run on any server, but then the AD FS service needs to be restarted ON EACH SERVER afterwards.
Be sure to close IE to clear the browser cache before trying after this fix.
- The SecurIDAuthProvider(MicrosoftIdentityServer...).log for the AD FS agent should now show the claim type to be UPN:
Workaround
Notes
Related Articles
Microsoft Office 365 - Configure Active Directory Sync - RSA Ready SecurID Access Implementation Guide 43Number of Views The Active Directory Account Collector does not collect the AD Domain Users Group in RSA Identity Governance & Lifecycle 216Number of Views RSA PAM Authentication Agent cannot challenge users in Active Directory groups 264Number of Views Can I have different analytic servers on the same network connecting to same SilverTap in RSA Web Threat Detection 6.1 5Number of Views When Active Directory is integrated using Winbind, group membership for Active Directory users fails with the RSA Authenti… 154Number of Views
Trending Articles
An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process
Don't see what you're looking for?