Identity Source
RSA Security Console
Administrators can logon to the RSA Security Console where a token is assigned to the administrator
Authentication Error
Your logon information is incorrect. Correct your logon information and try again, or contact the help desk or your administrator.
The user is residing in the RSA Authentication Manager database where the User ID appears not to have changed however it is possible that some other identifying data is referencing the user that is no longer available since the change made in the directory server.
Below are steps to flush the user from RSA Authentication Manager and map it back with correct identifiers.
NOTE: the user will be removed from RSA Authentication Manager v8.1 and will lose any token assignment(s) and/or administration role(s).
|
1. |
Ensure you have made a note on the token(s) and administrative role(s) assigned to the user.
| |
|
2. |
To remove a single user from the identity source mapping found in the RSA Operations Console an administrator would change the ?Directory Configuration- Users? filter from (&(objectClass=User)(objectcategory=person)) to (&(objectClass=User)(objectcategory=person)(!(samAccountName=<samAccountName>)))
NOTE: substitute <samAccountName> with the actual samAccountName of the user
Logon to the primary RSA Operations Console > Deployment Configuration > Identity Sources > Manage Existing ? select the Identity Source Name (left-click the mouse) > Edit > click the Map tab > change the Search Filter in the Directory Configuration- Users section.
Save and Finish and confirm the Change.
| |
|
3. |
After saving the change to the filter and confirming the change, an administrator would logon to the RSA Security Console and select Setup > Identity Sources > Clean Up Unresolvable Users ? select the Identity Source and uncheck the Grace Period > Next
This should find the User ID of the user that is no longer included in the identity source mapping and an administrator can then select the Clean Up Now button to remove this item (user) found.
| |
|
4. |
To ensure the user is made available to the RSA Authentication Manager an administrator would change the ?Directory Configuration- Users? filter back to the default (&(objectClass=User)(objectcategory=person)).
Logon to the primary RSA Operations Console > Deployment Configuration > Identity Sources > Manage Existing ? select the Identity Source Name (left-click the mouse) > Edit > click the Map tab > change the Search Filter in the Directory Configuration- Users section.
| |
|
5. |
Now, assign the user any previously assigned Administrative Roles (e.g. SuperAdminRole) and assign back any previously assigned token(s).
|
Related Articles
About the Security Console 209Number of Views Configure Security Console Authentication Methods 242Number of Views RSA SecurID Access pop up on RSA Security Console 30Number of Views Firefox reports Secure Connection Failed when connecting to the RSA Security Console 526Number of Views How to configure AES ciphers for the RSA Authentication Manager 8.1 Security Console 666Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)