RSA Authentication Agent 1.0.1 for Active Directory Federation Services (AD FS) sends domain\samAccountName instead of UPN to Authentication Manager
Originally Published: 2017-04-28
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Active Directory Federation Services (AD FS)
RSA Version/Condition: 1.0.1
Issue
- At the AD FS front end web page the customer enters their UPN such as jon.smith@company.com in the User Name field, along with their password.
- But ADFS prompts for a passcode with samAccountName, prefixed with the domain; for example, company\jon.smith instead.
- Since the user ID is in UPN format in Authentication Manager, the Domain\samAccountname format of the same user is not found, so logon fails with failure to resolve User ID or Alias.
Cause
The SecurIDAuthProvider(MicrosoftIdentityServer...).log for the AD FS agent will show the claim type, in this case windowsaccountname, when it should be UPN.
Resolution
- The ADFSUnregisterationSample PowerShell script should be in C:\Program Files\RSA\RSA Authentication Agent\AD FS Adapter\SampleRegistrationScripts.
- In PowerShell change directory to the ..\AD FS Adapter\SampleRegistrationScripts directory and run the ADFSUnregistrationSample.ps1 (or your customized) PowerShell script
- Follow this by running the ADFSRegistrationSample.ps1 (or your customized) PowerShell script
- If AD FS is running in a farm of AD FS servers, the (un)registration commands are run on any server, but then the AD FS service needs to be restarted ON EACH SERVER afterwards.
Be sure to close IE to clear the browser cache before trying after this fix.
- The SecurIDAuthProvider(MicrosoftIdentityServer...).log for the AD FS agent should now show the claim type to be UPN:
Workaround
Notes
Related Articles
Notification rule triggers daily for the same admin error in RSA Governance & Lifecycle 19Number of Views RSA Authentication Manager 8.4 responds to authentication requests coming from RSA Authentication Agent 2.0 for Active Dir… 36Number of Views Authentication to restricted agents with Active Directory users fail in Authentication Manager 8.1 146Number of Views Button Transition cannot be selected, modified nor deleted in RSA Governance & Lifecycle 11Number of Views Access Manager is unable to connect to Active Directory even after expired Domain Controller certificate is replaced 39Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?