RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
When an attribute is configured in Security Console under Identity > Users > Authentication Settings > RADIUS > RADIUS User Attributes, you may notice the attribute sent by RSA Authentication Manager to RADIUS client has both an attribute ID and an attribute name appended to the value.
For example:
- If you select 11 - Filter-ID" from Attribute and set "policy_GRP_1 as the value, the attribute contained in RADIUS response message is:
Filter-ID=ATTR11_Filter-ID=policy_GRP_1
- If you select 18 - Reply-Message from Attribute and set GRP as the value, the attribute contained in RADIUS response message is:
Reply-Message=ATTR1_Reply-Message=GRP
On the other hand, if you set a RADIUS profile in RADIUS > RADIUS Profiles, then link it with a user or agent, the attribute sent by RSA Authentication Manager to RADIUS client contains just the value. For example, if you select Filter-ID[M] for Attribute and set policy_GRP_I as the value, the attribute contained in RADIUS response message is:
Filter-ID=policy_GRP_
The issue is that the attribute format of attribute_id+attribute_name+attribute_value may not be accepted by RADIUS clients.
For RSA Authentication Manager 7.1, see steps provided in the Notes section, below.
For Authentication Manager 8.x:- Login to the Security Console.
- Navigate to Setup > System Settings > RADIUS.
- Check the option to Send user´s RADIUS attributes to the RADIUS server upon successful authentication.
- You can then set the RADIUS Attribute Format. Select one of three options. Use the above example for reference, where 11 - Filter-ID is Attribute and policy_GRP_1 is set as value.
- Send attribute ID, attribute name, and attribute value
Filter-ID=ATTR11_Filter-ID=policy_GRP_1
- Send attribute name and attribute value
Filter-ID=Filter-ID=policy_GRP_1
- Send attribute value only
Filter-ID=policy_GRP_1
- Click Save when done.
Related Articles
On systems where the BINDING_ATTR value has been changed should the USERID_ATTR value also be changed? 8Number of Views Trusted Network policy attribute does not work correctly with applications configured after disabling Identity Confidence … 71Number of Views Entitlements missing in PV_USER_DIRECT_ACCESS view in RSA Identity Governance & Lifecycle 71Number of Views User-type user attributes show internal ID values instead of UserID values in RSA Identity Governance & Lifecycle 68Number of Views How to Manually Upload Files and Recreate the Securty Analytics 10.X YUM Repository 925Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)