The changes below create a rule which fires when a user is in a NiotEnrolled status. It can easily be modified to triiger on other conditions such as a user who is locked out.
In the policy rules file signinDeviceOnly.drl at the top in the import section add the following:
<import>com.passmarksecurity.api.UserStatus</import>
<import>com.rsa.csd.api.RsaUser</import>
Then in the main section of rules add the following new rule:
<!--
Detect users who are not enrolled
-->
<rule no-loop="true" salience="999">
<parameter identifier="facts">
<class>com.rsa.csd.api.facts.Fact</class>
</parameter>
<parameter identifier="risk">
<class>AuthRiskResult</class>
</parameter>
<java:condition>
((RsaUser)facts.getValue("user.legacyObject")).getStatus().toString().equals(UserStatus._NOTENROLLED)
</java:condition>
<java:consequence>
drools.retractObject(facts);
drools.retractObject(risk);
</java:consequence>
</rule>
Finally in c-config-forensic.xml create a policy for the new rule:
<entry key="NotEnrolled">
<value>ALLOW</value>
</entry>
Related Articles
Moving Users in an LDAP Directory 36Number of Views Unlock a User in the User Dashboard 22Number of Views Move Users Between Security Domains 25Number of Views Move RSA Authentication Manager 8.1 users from the internal database to an external identity source along with their group… 525Number of Views 'Request could not be handled' error reverting a Role that has been moved to a different Role Set in RSA Identity Governan… 56Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Governance & Lifecycle Generic Database Collector Guide RSA Authentication Manager 8.7 SP2 Administrator's Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager 8.9 Setup and Configuration Guide