RSA Authentication Agent for Microsoft Windows: Domain users are not challenged when "Domain Users" group is nested in local "Users" group
Originally Published: 2018-07-05
Last Modified: 2023-09-22
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.2.1.41 or later, 7.3, 7.3.1, 7.3.2, 7.3.3
Issue
2018-06-28 10:40:23.796 The Challenge Group sAMAccountName policy is .\Users
2018-06-28 10:40:23.796 There is no Enable Challenge policy or preference configured. DoNotEnableChallenge is being used as the programmatic default.
2018-06-28 10:40:23.796 Preference value for "FailOpen" doesn't exist.
2018-06-28 10:40:23.796 There is no Fail Open policy or preference configured. DoNotLocallyCacheUserChallengeType is being used as the programmatic default.
2018-06-28 10:40:23.796 groupDomainORworkstationName = workstation1, groupName = Users
2018-06-28 10:40:23.796 userDomainORworkstationName = domainA, userName = user123, fullGroupName = .\Users
2018-06-28 10:40:26.063 wsUserADsNTPath = WinNT://domainA/user123
2018-06-28 10:40:26.063 Recursively check group name: WinNT://workstation1/Users
2018-06-28 10:40:26.063 CheckDomainUserInLocalGroup] for user: WinNT://domainA/user123
2018-06-28 10:40:26.063 [ADSIHelper::StringSID] Domain name: domainA
2018-06-28 10:40:26.063 The user's compared String SID is WinNT://S-1-5-21-1687131260-2929665233-840903075-2196
2018-06-28 10:40:26.063 Fetched 0x4 group members, now looping through them.
2018-06-28 10:40:26.063 Nested group found: WinNT://NT AUTHORITY/INTERACTIVE
2018-06-28 10:40:26.063 wsGroupNTPath = WinNT://NT AUTHORITY/INTERACTIVE, gpDomainORworkstationName = , gpName =
2018-06-28 10:40:26.063 [ADSIHelper::ParseGroupName] fullGroupPath = NT AUTHORITY/INTERACTIVE
2018-06-28 10:40:26.063 groupDomainORworkstationName = NT AUTHORITY, groupName = INTERACTIVE
2018-06-28 10:40:26.063 The group is assumed to be a domain group
2018-06-28 10:40:26.063 Got interface to nested domain group, calling isUserMemberOfGroup() to check the group.
2018-06-28 10:40:26.220 Failed to set NT4 Name = NT AUTHORITY\INTERACTIVE
2018-06-28 10:40:26.220 Caught HRESULT:Cause
Resolution
Call RSA Technical Support to obtain this hotfix.
Workaround
Challenge: All users except
Group: .\Administrators
Related Articles
Registry setting for Send Domain Name option for RSA Authentication Agent 7.x for Windows 35Number of Views Self-Service Troubleshooting Policy 28Number of Views Customize and Configure Domain Name 205Number of Views Delete Default Security Domain Mappings 6Number of Views Send both user name and domain name to the server during an RSA Authentication Agent for Windows authentication request 179Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?