How to suppress a 401 authentication prompt in SharePoint 2010 for excluded resources
Originally Published: 2013-03-07
Article Number
Applies To
Issue
Cause
Resolution
This fix introduces a new parameter that allows you to designate resources that are excluded, but where you still wish to have the Protocol Transition credentials expressed.
# Specifies Microsoft application directory resources that
# are given anonymous access in SharePoint and excluded or
# unprotected in Access Manager. When the request for these set
# of Url's are made and the user already has a valid CTSESSION,
# then the agent would set the impersonation token to make
# sure that SharePoint does not fail these requests with "401 unauthorized".
#
# Allowed Value:
# Comma-separated Microsoft application virtual directory
# resources in IIS.
#
# Example:
# cleartrust.agent.iis.msapp_anonymous_resource_list=/Lists/Calendar/*
#
# Dependencies:
# This parameter needs to be configured if this web server hosts Microsoft
# applications that need SSO with other RSA ClearTrust protected resources
# and the SharePoint resources with anonymous access is excluded in Agent.
#
# Note: Set this parameter only if the SharePoint pages are configured
# anonymous access and excluded from Access Manager agent.
#
cleartrust.agent.iis.msapp_anonymous_resource_list=
Notes
Note that the RSA Agent can only express credentials if the use has a valid RSA Access Manager authenticated session and a valid CTSESSION cookie. The CTSESSION cookie is only updated when the user is actively browsing protected content. If the user attempts to browse excluded content longer than time set in the agent idle timeout setting, without accessing any protected content, then the users session will be invalidated. In these situations RSA Access Manager will no longer be able to express the Protocol Transition credentials and the user will then be presented with a 401 authentication prompt.
Related Articles
Error: 'Cannot find 'file:D'/docs/release_notes/release_notes.html'. Make sure the path or Internet address is correct.' i… 11Number of Views Forgot the password used to compress and encrypt a file with RSA SureFile 18Number of Views Technical/Business Owner of Application/Directory Couldn't edit Groups in SecurID Governance & Lifecycle 30Number of Views RSA Identity Governance and Lifecycle SSL connectivity fails and throws 'Certificates does not conform to algorithm constr… 142Number of Views AFX Server is in a 'Not running' State in the user interface but 'afx status' indicates AFX is running in RSA Identity Gov… 371Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?