RSA Product/Service Type: Authentication Manager & MFA Agent for Microsoft Windows
RSA Version: 8.7 SP1 and above (Authentication Manager) & 2.2.1 and above (MFA Agent for Microsoft Windows)
Windows password retrieval failed
Agent <Agent Name> is unable to retrieve Windows password for user <UserID>
JWT token has expired.
The time is not in sync between the Authentication Manager server(s) and the machine the MFA Agent for Windows is installed on.
Correct the time between the Authentication Manager server(s) and the machine the MFA Agent for Windows is installed on.
If the time on any of the Authentication Manager server(s) needs to be adjusted and is off by more than a couple of minutes, contact RSA Customer Support for assistance before proceeding. See the "Update System Date and Time Settings" page if adjusting the time on the Authentication Manager server(s) is needed.
----------------------------------------------------------------------------------------------------------------
Correcting the time between the Authentication Manager server(s) and machine the MFA Agent for Windows is installed on should typically resolve this issue, but if it does not, then there is a command line utility that can be run from the Primary Authentication Manager server to increase the time skew allowed between the server and agent machines. To run this command:
1. Log into the command line of the Primary Authentication Manager server.
2. Run the following command: /opt/rsa/am/utils/rsautil store -a update_config auth_manager.agent.max_clock_skew.seconds <skew allowed in seconds> <Primary Authentication Manager FQDN>
Note: The default "skew allowed in seconds" is 5.
Related Articles
RSA MFA Agent for Windows will not run due to error "This module is blocked from loading into the Local Security Authority" 800Number of Views Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … 1.2KNumber of Views Troubleshooting RSA MFA Agent for Microsoft Windows 4.04KNumber of Views Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … 295Number of Views AFX Server remains in a 'Not running' State, afx status shows 'timed out waiting for AFX applications to start' and mule_e… 3.51KNumber of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle