RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
When attempting to perform user management tasks in the RSA Authentication Manager Security Console, administrators receive the following error and are unable to complete the action:
Cannot add or manage a user with user ID <UserID>. User IDs must be unique within a deployment. This user ID is already in use." while taking any actions such as assigning tokens, adding groups, permissions etc to a user id with duplicate userid in realm,
This error may occur when attempting any of the following actions on the affected user:
- Assigning a token to the user
- Adding the user to a group
- Editing user account details
- Any other administrative task targeting the specific user account
This error occurs when RSA Authentication Manager detects a duplicate user ID across one or more identity sources in the deployment. There are three known conditions that trigger this error:
- Cause 1 — Duplicate user entries across identity sources: The same user ID exists in more than one identity source linked to Authentication Manager. The system cannot determine which entry to act on and blocks the operation.
- Cause 2 — Unresolvable LDAP user: An LDAP identity source contains a user record that Authentication Manager cannot fully resolve — for example, due to a corrupted or incomplete directory entry. The system flags the user ID as conflicting.
- Cause 3 — Intentional duplicate user requirement: The deployment is configured to support duplicate user IDs across identity sources by design. In this case, the error is expected behavior, and a configuration change is required to allow the operation.
Resolution for Cause 1 — Duplicate User Entries Across Identity Sources
- Log in to the RSA Authentication Manager Security Console.
- Navigate to Identity > Users > Manage Existing.
- Under Search Criteria, select Search for users across all identity sources.
- Enter the affected User ID in the search field.
- Click Search to run the query.
- Review the search results. If multiple entries appear for the same User ID, identify the correct user entry — confirm the identity source, associated tokens, and group memberships to determine which record to keep.
CAUTION: The next step permanently deletes user entries. Deleting the wrong record may remove token assignments and group memberships that cannot be automatically recovered. Verify the correct entry before proceeding.
- Delete all duplicate user entries except the correct one.
- Verify — Retry the original administrative task (e.g., assign token, add to group) on the remaining user entry. Confirm the error no longer appears.
Resolution for Cause 2 — Unresolvable LDAP User
Follow the steps in Resolving Unresolvable LDAP User Entries in RSA Authentication Manager to identify and resolve the corrupted or incomplete LDAP directory record causing the conflict.
Verify — After completing the steps, retry the original administrative task on the affected user. Confirm the error no longer appears.
Resolution for Cause 3 — Intentional Duplicate User Requirement
Follow the steps to update your deployment configuration to allow the intended duplicate user scenario.
- Log in to the Security Console.
- Click Setup > System Settings.
- Click Security Console Authentication Methods under Console and Session Settings.
- Check the option for Non-Unique User IDs to allow identical User IDs may exist in more than one identity source.
- Click Save.
Verify — After completing the steps, retry the original administrative task on the affected user. Confirm the operation completes successfully.
Related Articles
RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.23KNumber of Views Duplicate User ID error when running All Users report in RSA Authentication Manager 8.x 1.73KNumber of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.15KNumber of Views AM 8.1: Cannot add or manage a user with user ID <UserID>. User IDs must be unique within a deployment. This user ID is al… 320Number of Views Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU 1.96KNumber of Views
Trending Articles
RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Customizing TLS Protocol Version RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Release Notes for RSA Authentication Manager 8.8