Unable to use the User Scope Restriction in RSA Authentication Manager 8.x
Originally Published: 2015-04-20
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
There was a problem processing your request. Specified scope restriction condition PRINICIPAL.<attributename> IN
{“<myvalue>”} is invalid.
{“<myvalue>”} is invalid.
The User Scope Restriction allows you to restrict which users the administrator can manage within the administrative scope of this role. To restrict user scope, you must specify an attribute condition.
Cause
Resolution
Confirm that the User to define conditions on administrative user management permission is checked as shown above.
Once you have an attribute defined to use for scope restriction and this option checked then you will be able to use User Scope Restriction in Administrative roles.
In this instance, this option was not checked, triggering the error.
Notes
- The syntax is PRINICIPAL. IN {“”}
- The syntax is case sensitive. PRINCIPAL and IN are always uppercase. The attribute name should be exactly what you mentioned when creating the attribute above.
- For example, if you create an attribute name called Department, then your syntax will look something like PRINCIPAL.Department IN { "RESEARCH"}.
- Using PRINCIPAL.DEPARTMENT IN { "RESEARCH"} will fail.
- The working syntax here will give the administrative role to admin who can manage users from research department.
Related Articles
Display sequence incorrect while trying to use custom user object dashboard in RSA Identity Governance & Lifecycle 35Number of Views VIA L&G What is the meaning of the NONE button in bulk review 25Number of Views Entitlement View does not scope correctly when triggered via request buttons in RSA Identity Governance & Lifecycle 16Number of Views Setting RADIUS attributes to use with the Telstra Next G wireless service 171Number of Views How to use the ${GeneratedPassword} value in an Active Directory Account Template in RSA Identity Governance and Lifecycle… 199Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?