Unified Directory Identity Sources
13 hours ago

Unified Directory Identity Sources

RSA Unified Directory is a user identity store for the RSA Cloud Access Service (CAS) that enables full Cloud-only deployments. Users and their passwords can be created and stored as "Local" in the Cloud without an external identity source. Additionally, the open-standard System for Cross-Domain Identity Management (SCIM) API can be used to provision users into CAS without requiring an on-premise or Cloud-based installation of any RSA software.

It is designed to be highly flexible and extensible, supporting various customer personas and their specific data sets. To support group-based application access, Unified Directory users can also be associated with local groups. RSA Unified Directory also allows you to manage identities directly within the system, providing a streamlined approach to workforce identity management.

 

RSA Unified Directory includes the following types of identity sources:

  • Local: User data is stored within CAS and can be added through various methods, including the Cloud Administration Console, importing a CSV file, or a one-time per user SCIM push.

  • SCIM Managed: User data is stored within CAS, while user management is conducted via an external identity source. This type can connect to any identity source that supports SCIM.

  • Azure Active Directory (SCIM): A special case of the SCIM Managed type that is limited to be used only with Azure Active Directory (AD).

  • RSA Authentication Manager (AM) Internal Database: Enables CAS to leverage one AM server's internal database of users as an identity source. When user synchronization is configured in the AM Security Console, an identity source is automatically created in CAS and appears in the Cloud Administration Console.

The following table summarizes the distinction between these types:

 

Identity Source Type Password Storage & AuthenticationPassword Change/Reset PasswordUser Management
Local
  • CAS

  • My Page

  • Cloud Administration Console

  • CAS Cloud Administration Console

SCIM Managed
  • CAS
    Or

  • An external identity source

  • My Page

  • An external identity source

  • Cloud Administration Console

  • An external identity source

  • Cloud Administration Console

Azure Active Directory (SCIM) with a password in Azure
  • Azure AD 

  • Azure AD 

  • Azure AD Cloud Administration Console

Azure Active Directory (SCIM) with a password in RSA Directory
  • CAS

  • My Page

  •  CASAdministration Console

  • CAS Administration Console

RSA Authentication Manager (AM) Internal Database
  • CAS

    And

  • AM Server

  • My Page

  • AM Self-Service Console

  • Cloud Administration Console

RSA AM Security Console

This topic includes the following:

Add a Local Identity Source

This section explains how to add a Local identity source. You can create users locally by directly entering them via the Cloud Administration Console, importing CSV files, or provisioning them from an external source through the SCIM API, if available with your ID Plus License. For more information, see User Provisioning Using SCIM API.

Note:  Local identity sources are available for all ID Plus subscriptions. Utilizing SCIM provisioning in Local identity sources and adding SCIM Managed identity sources are available only for ID Plus E2 and E3 subscriptions.

Procedure 

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Click Add an Identity Source.

  3. Click Select next to Local identity source type.

  4. In the Identity Source Name field, enter a name for the identity source.

  5. (Optional) In the Description field, enter a description for the identity source.

  6. The Enable User Provisioning from a SCIM Identity Source field is set to Yes by default.

    1. (Optional) In the External SCIM ID Source Admin URL field, enter the URL from which the administrator can manage the SCIM identity source.
    2. In the SCIM Service Provider Base URI field, click Copy URI to copy the URI to which the SCIM API client sends details. Paste this URI into the configuration settings of the SCIM identity source to connect it to a specific CAS tenant.
    3. For the SCIM Service API key field, click Generate Key to generate the Service API key used for SCIM API authentication. Then, copy this key and paste it into the configuration settings of the SCIM identity source to connect to a specific CAS tenant.
    4. For the OAuth option, select a preconfigured SCIM API from the Client API list. For more information, see Manage OAuth API Clients.

      Note:  Based on your identity source configuration, configure either OAuth (recommended) or an API key for SCIM API access.

    5. In the Network Zone field, select a network zone from the drop-down menu to manage trusted or restricted IP addresses for the SCIM connection. Network zones enable you to allow or restrict specific IPs for SCIM connectivity with CAS. For more information, see Manage Networks .

  7. In the Password Type section, select one of the following options:

    1. RSA Unified Directory to store a password in CAS that enables users to authenticate with their password directly against CAS via an authentication interface (for example, RSA or third-party applications, RADIUS, or web authentication).

      By default, this option is selected. In the RSA Password field, select one of the following: 

      • Required if the password attribute is mandatory when provisioning a user. If the password is not provided in a user provisioning request, user provisioning will fail.

      • Allowed if the password attribute is not mandatory when provisioning a user.

      Then, in the Initial Password Creation Options section, enable at least one of the following options for creating passwords:

      • Entered by Admin to enable administrators to manually set initial user passwords.

      • Generated by CAS if you want CAS to generate a random initial password for users. Then, in the Send Initial Password Options section, select how passwords will be provided to users:

        • Email to send an initial password to the user's email address. This option can be used for users added through the "Add a User" option (Users > Management), CSV import, or SCIM API.

        • Display on Screen to Admin CAS will generate a random password. Then, the administrator can copy the automatically generated password and send it to users. This option only applies to users added to Local identity sources via the "Add a User" option (Users > Management) in the Cloud Administration Console. For more information, see the Add a User in the Unified Directory section on the Manage Users for the Cloud Access Service page.

      Note:  The Initial Password Creation Options apply only to Local identity sources.

    2. No Password Available to CAS for authentication users will not be able to store passwords associated with their Cloud-based identity source account. In this case, CAS does not store or validate users' passwords. This option should be selected when authentication does not require a password, or if password validation will be performed by an external Identity Provider (IdP), rather than CAS. For information about configuring an identity provider, see Adding Identity Providers.

  8. On the User Synchronization & Attributes tab, Local identity sources use the native CAS schema and do not require user attribute mappings. Core and additional user attributes can be synchronized to the CAS Common User Schema for use in Policies & Applications. Select the checkbox in the Policies & Applications column to synchronize an attribute with CAS.

  9. Click Save.

  10. Click Publish Changes to activate the identity source.

Import Users to a Local Identity Source

The Cloud Administration Console allows you to import users in the form of a comma-separated values (CSV) file to a Local identity source. When importing users, you need to download and use the sample CSV file for the specific identity source as a template.

The template also includes additional common user attributes, such as Business Category, Company or Organization, Country Code, Department, Description, Display Name, Employee Number, Employee Type, Full Name, Home Email, Mobile, and Work Phone, if your deployment uses the common user schema.

Procedure 

  1. In the Cloud Administration Console, navigate to Users > Identity Sources or Users > Management.

If accessing through Users > Identity Sources:

  • On the Identity Sources page, locate the desired local identity source.
  • Select Import Users from the drop-down menu.

If accessing through Users > Management:

  • On the User Management page, click the Import Users button.

  • Choose the identity source where the users should be imported.

  1. Click the Download CSV template button.

  1. Add the users into the downloaded template and save it with a unique name.

  2. In the User CSV File field, click Choose File, navigate to the CSV file, and then click Open.

  3. Click Import.

CAS validates that a CSV file is formatted correctly and that all the attribute requirements are met during the import. If there are errors with any row, those rows will be skipped and valid rows will be imported. CAS will generate an error file that can be downloaded immediately after the import attempt is complete. This file contains all rows with errors and a column listing the specific error(s) for each row for the administrator to fix them.

Note:  If the file is not immediately downloaded, it will not be available again. In this case, the administrator should either leave the page or reload it without downloading the error file.

After correcting any errors, the administrator should delete the error column and attempt to upload the corrected file. This process can be repeated multiple times until either all errors are corrected or all users are successfully imported.

Add a SCIM Managed Identity Source

This section explains how to add a SCIM Managed identity source. You can provision users from an external source using SCIM APIs, and users can only be managed from that external source and not via the Cloud Administration Console.

Procedure 

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Click Add an Identity Source.

  3. Click Select next to the SCIM Managed identity source type.

  4. In the Identity Source Name field, enter a name for the identity source.

  5. (Optional) In the Description field, enter a description for the identity source.

  6. The Enable User Provisioning from a SCIM Identity Source field is set to Yes by default.

    1. (Optional) In the External SCIM ID Source Admin URL field, enter the URL from which the administrator can manage the SCIM identity source.
    2. In the SCIM Service Provider Base URI field, click Copy URI to copy the URI to which the SCIM API client sends details. Paste this URI into the configuration settings of the SCIM identity source to connect it to a specific CAS tenant.
    3. For the SCIM Service API key field, click Generate Key to generate the Service API key used for SCIM API authentication. Then, copy this key and paste it into the configuration settings of the SCIM identity source to connect to a specific CAS tenant.
    4. For the OAuth option, select a preconfigured SCIM API from the Client API list. For more information, see Manage OAuth API Clients.

      Note:  Based on your identity source configuration, configure either OAuth (recommended) or an API key for SCIM API access.

    5. In the Network Zone field, select a network zone from the drop-down menu to manage trusted or restricted IP addresses for the SCIM connection. Network zones enable you to allow or restrict specific IPs for SCIM connectivity with CAS. For more information, see Manage Networks .

  7. In the Password Type section, select one of the following options:

    1. RSA Unified Directory to store a password in CAS that enables users to authenticate with their password directly against CASvia an authentication interface (for example, RSA or third-party applications, RADIUS, or web authentication). Selecting this option means that users will have a separate password from the one in the external identity source. This option can be selected under the following conditions:

      • The SCIM identity source supports provisioning passwords, and one will be sent to CAS.

      • The SCIM identity source supports provisioning passwords, but will not send one to CAS, yet creating a password in CAS is desired.

      • The SCIM identity source does not support provisioning passwords, but creating a password in CAS is desired.

      In the RSA Password field, select one of the following:

      • Required if the password attribute is mandatory when provisioning a user. If the password is not provided in a user provisioning request, user provisioning will fail.

      • Allowed if the password attribute is not mandatory when provisioning a user.

      Note:  The Initial Password Creation Options apply only to Local identity sources.

    2. No Password Available to CAS for authentication this option is selected by default. Users will not be able to store passwords associated with their Cloud-based identity source account. In this case, CAS does not store or validate users' passwords. This option should be selected when authentication does not require a password, or if password validation will be performed by an external Identity Provider (IdP), rather than CAS. For information about configuring an identity provider, see Adding Identity Providers.

  8. On the User Synchronization & Attributes tab, select values from the drop-down lists in the SCIM User Attribute column to modify the default attribute mappings between a SCIM-managed identity source and the CAS common schema. Select the checkbox in the Policies & Applications column to control whether an attribute is synchronized with CAS.

  9. Click Save.

  10. Click Publish Changes to activate the identity source.

Add an Azure Active Directory (SCIM) Identity Source

This section explains how to add a new Azure Active Directory identity source. You can provision users in a Microsoft Azure Active Directory (now known as Microsoft Entra ID) through the SCIM APIs based on the created identity source type and your subscription. For more information, see User Provisioning Using SCIM API.

Note:  The ability to add Azure Active Directory (SCIM) is available for all ID Plus subscriptions. If a password exists for the user in Azure Active Directory, CAS users cannot authenticate using that password. Optionally, you can configure a separate password specifically for CAS authentication. Refer to step 7 below for instructions.

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Click Add an Identity Source.

  3. Click Select next to the Azure Active Directory (SCIM) identity source type.

  4. In the Identity Source Name field, enter a name for the identity source.

  5. (Optional) In the Description field, enter a description for the identity source.

  6. The Enable User Provisioning from a SCIM Identity Source field is set to Yes by default.

    1. (Optional) In the External SCIM ID Source Admin URL field, enter the URL from which the SCIM API client (Azure Active Directory SCIM) sends details.
    2. In the SCIM Service Provider Base URI field, click Copy URI to copy the URI to which the SCIM API client (Azure Active Directory SCIM) sends details.
    3. For the SCIM Service API key field, click Generate Key to generate the Service API key used for SCIM API authentication.
    4. For the OAuth option, select a preconfigured SCIM API from the Client API list. For more information, see Manage OAuth API Clients.

      Note:  Based on your identity source configuration, configure either OAuth (recommended) or an API key for SCIM API access.

    5. In the Network Zone field, select a network zone from the drop-down menu to manage trusted or restricted IP addresses for the SCIM connection. Network zones enable you to allow or restrict specific IPs for SCIM connectivity with CAS. For more information, see Manage Networks .

  7. In the Password Type section, select one of the following options:

    1. RSA Unified Directory to store a password in CAS that enables users to authenticate with their password directly against CAS via an authentication interface (for example, RSA or third-party applications, RADIUS, or web authentication). Selecting this option means that users will have a separate password from the one in Azure AD. This option is selected by default.

      In the RSA Password field, select one of the following: 

      • Required if the password attribute is mandatory when provisioning a user. If the password is not provided in a user provisioning request, user provisioning will fail.

      • Allowed if the password attribute is not mandatory when provisioning a user.

      Then, in the Initial Password Creation Options section, enable one of the following options to create passwords:

      • Entered by Admin if you want to enter passwords for users.

      • Generated by CAS if you want CAS to generate a random initial password for users. Then, in the Send Initial Password Options section, select how passwords will be provided to users:

        • Email if you want to send an initial password to the user's email address. This option can be used for users added through the "Add a User" option (Users > Management), CSV import, or SCIM API.

        • Display on Screen to Admin if you want the CAS to generate a random password. Then, you can copy the automatically generated password and send it to users. This option only applies to users added to local identity sources via the "Add a User" option (Users > Management) in the Cloud Administration Console. For more information, see the "Add a User in the Unified Directory" section on the Manage Users for the Cloud Access Service page.

      Note:  The initial password creation options apply only to local type identity sources.

    2. No Password Available to CAS for authentication if you select this option, users will not be able to store passwords associated with their Cloud-based identity source account. In this case, the CAS does not store or validate users' passwords. For information about configuring an identity provider, see Adding Identity Providers.

  8. On the User Synchronization & Attributes tab, select values from the drop-down lists in the SCIM User Attribute column to modify the default attribute mappings between the Entra ID identity source and the common schema. Select the checkbox in the Policies & Applications column to control whether an attribute is synchronized with CAS.

  9. Click Save.

  10. Click Publish Changes to activate the identity source.

Edit an RSA Authentication Manager Internal Database Identity Source

CAS has the capability to utilize users stored in a single AM server's internal database as an identity source. While users can only be managed within the AM database, passwords can be bi-directionally synced and managed either in AM or CAS.

In the AM Security Console, when users are fully synchronized from internal database to CAS, a new "RSA Authentication Manager Internal Database" identity source will be created automatically in CAS. For more information, see the "User Synchronization" section in "Chapter 6: Deploying Cloud Authentication in the Authentication Manager 8.7 SP2 Administrator's Guide. Only one identity source of this type can be configured per CAS tenant.

CAS allows users to change or reset their passwords, and their passwords are synchronized back to AM.

Before you begin 

This feature requires a configured connection from AM to the RSA CAS and is not available if there is only a connection from the RSA CAS to AM or a legacy connection from AM to the identity routers. For more information, see the following:

Procedure 

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Click Edit next to the RSA Authentication Manager Internal Database identity source.

  3. The Identity Source Name is set by AM during the initial configuration to CAS for user synchronization. Once set, it cannot be changed from either location without deleting all users and their credentials from CAS.

  4. (Optional) In the Description field, enter a description for the identity source.

  5. In the Password Type section, select one of the following options:

    1. RSA Authentication Manager Server (synced to CAS) to store a password in CAS that enables users to authenticate with their password directly against CAS via an authentication interface (for example, RSA or third-party applications, RADIUS, or web authentication). By default, this option is selected. In the RSA Password field, select one of the following: 

      • Required if the password attribute is mandatory when provisioning a user. Users without a password in the AM Database will not be synced to CAS.

      • Allowed if the password attribute is not mandatory when provisioning a user. Users will be synced regardless of whether they have a password.

    2. No Password if you want an identity provider to authenticate users. In this case, CAS does not validate users' passwords. For information about configuring an identity provider, see Adding Identity Providers.

  1. On the User Synchronization & Attributes tab, Authentication Manager Internal Database identity sources uses the native CAS schema and do not require user attribute mappings. Core and additional user attributes can be synchronized to the Common User Schema for use in Policies & Applications. Select the checkbox in the Policies & Applications column to synchronize an attribute with CAS.

  2. Click Save.

  3. Click Publish Changes to activate the identity source.

Convert RSA Authentication Manager Internal Database Identity Source to a Local Identity Source

You can convert an RSA Authentication Manager Internal Database identity source to a Local identity source if you want to migrate from AM to a CAS-only deployment while retaining existing users and credentials. After the conversion, you can manage users and credentials directly in CAS.

Before you begin 

You can convert an RSA Authentication Manager Internal Database identity source to a Local identity source if you have migrated to the Common User Schema.

Procedure 

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Locate the Authentication Manager Internal Database identity source that you want to convert. Click the down arrow next to the identity source, and then select Convert to Local.

  3. Click Proceed.

After the conversion completes successfully, it becomes a Local identity source. You can manage users and set initial passwords in the same way as other local identity sources.

Authentication Manager no longer synchronizes users to CAS, and you can clear the Synchronize Internal Database Users to Cloud Authentication Service (CAS) Using Security Domains option in AM. For more information, see Synchronize Users from Internal Database to Cloud Authentication Service.

Add a User in the Unified Directory

You can use the Cloud Administration Console to create a user in the Unified Directory. You can add the users’ details and set their initial passwords. Users can then log on to My Page and change their assigned password.

RSA makes an effort to prevent the use of passwords that are publicly listed as compromised in known data breaches. User passwords are compared against the list of compromised passwords provided in the file available at https://www.ncsc.gov.uk/static-assets/documents/PwnedPasswordsTop100k.txt. RSA also regularly monitors for updates to the compromised password list and refreshes it as necessary.

Procedure 

  1. In the Cloud Administration Console, click Users > Management.

  2. On the User Management page, click Add a User.

  3. Enter the following information:

User InformationDescription
Identity SourceSelect the user's identity source for CAS. This field is required.
First Name, Last Name, Username, Alternate Username, Email Address

Enter the information that identifies the user. First Name, Username, and Email address fields are required.

Last Name and Alternate Username fields are optional.

Manager's EmailEnter the email address of the user's manager. This field is optional.
Group MembershipEnter the group name(s) in which that user is currently a member of. This field is optional.

SMS Phone

Voice Phone

Enter the user phone numbers. These fields are optional.

Password Creation,
Password, Confirm Password

In the Password Creation field, the following options can be available based on the enabled options for initial password creation:

  • Admin Entered

  • Generate & Display

  • Generate & Send

  • None

For information about how to enable the initial password creation options, see the "Add a Unified Directory Identity Source" section on the Unified Directory Identity Sources page.

Type and confirm the password that the user will use for authentication. The password must meet the password policy requirements; the password must be between 10 and 64 characters. Users can change their initial or first-time passwords when they log on to My Page. These fields are required.

  1. Click Create User.

Edit User Details in the Unified Directory

You can edit the details of users that belong to Local identity sources and were created using the SCIM API or the Cloud Administration Console.

Procedure 

  1. In the Cloud Administration Console, click Users > Management.

  2. In the Search field, enter the User ID and find the user that you want to edit.

  3. Click Edit.

  4. Edit the following attributes:

  • Last Name

  • Username

  • Alternate Username

  • Email Address

  • Group Membership (you can provide more than one group name)

  • SMS Phone

  • Voice Phone

  • Manager's Email

 

Password Management Policy for Unified Directory Users

  • RSA Unified Directory complies with the latest NIST 800-63B guidelines, which recommend not rotating passwords unless a breach is suspected. Password rotation reduces security as users engage in poor security behaviors when passwords must be changed periodically.

  • A user's password is stored in the Unified Directory using a salted one-way hash.

  • Password length must be between 10 and 64 characters.

User Attributes

User Attributes within the identity source can be reviewed and applied in policies and application configurations based on the following criteria.

  1. The attributes selected in the Policies column will be available for the following purposes:

    • Access Policy Rules: User Attributes

    • IDR SSO Agent Trusted Headers and HTTP Federation: Custom Headers

    • My Page > My Applications (SAML): User Identity and Statement Attributes

    • Relying Party (SAML): User Identity and Statement Attributes

    • RADIUS > RADIUS Profile: Return List Attributes

    • My Page > Enrollment and Recovery Validation Code Settings: Source for Email Address

  2. The attributes selected in the Apps column will be available for the following purposes:

    • IDR SSO Agent (SAML): User Identity and Statement Attributes

 

Disable a Unified Directory Identity Source

When you disable a Unified Directory identity source, you cannot edit its existing users or add new ones, and existing users will not be able to authenticate or access My Page.

Procedure 

  1. In the Cloud Administration Console, click Users > Identity Sources.

  2. Find the name of the Unified Directory identity source you want to disable and select Disable from the drop-down menu.
  3. Click Disable in the dialog box that appears.

  4. Click Publish Changes to activate the settings immediately.