Users from an external identity source are listed as disabled in the RSA Authentication Manager 8.x Security Console
Originally Published: 2016-08-20
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Cause
As Authentication Manager cannot determine if the account is enabled or not, for security reasons, it will interpret that the account is disabled.
Resolution
- Update the service account with a user that has domain admin permission to bind to the identity source.
- Ensure that the Directory User ID configured to bind to the LDAP directory in the Operations Console has read permissions for all user account controls in the LDAP branch that has been specified.
- From the Operations Console,
- Navigate to Deployment Configuration > Identity Sources > Manage Existing.
- Click on the context arrow next to the external identity source in question and click Edit.
- Update the Directory User ID field to a user that has appropriate domain permissions.
Related Articles
How to create an external identity source to Active Directory in RSA Authentication Manager 8.x 1.83KNumber of Views java.security.NoSuchAlgorithmException: SHA-256 MessageDigest not available 31Number of Views Enabled and Disabled Tokens 13Number of Views Replica not listed in Primary Console 26Number of Views How to exclude RSA Authentication Manager 8.x from picking up disabled user account data from the Microsoft LDAP directory 162Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to Download OTP Token Seed Files from myRSA RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?