
ChristopherBrosz39878 (Customer) asked a question.
Windows Password Integration (WPI) on MFA Agent 2.3.2
I am trying to migrate from Auth Agent 7.4.6 to MFA Agent 2.3.2 and I would like to keep the WPI feature.
I cant seem to get the agent to only ask for the Pin+Token method since upgrading.
I am using the Rest API, and for the registered agent I am using a generic name that maps to a authorized agent. The machines authenticate but always ask for both Pin/Token and Windows Password.
What am I missing? Or is this feature not supported?
Hello Christopher; You don't mention what version of the AM server you are running.
I am on the latest 8.7 SP2
Seeing the same issue with roughly the same software. We've configured the settings according to the manual with no luck.
I opened a case with RSA and spent a few hours on the phone.
We verified on the agent logging that WPI (Which you can search for in the log) was enabled was failing to fetch the password.
We tried setting after setting with no luck. (Click Expand to Read More)
At one point I had tested manually adding a agent with a machine name (FQDN) and IP. This is what we used for testing. When it seemed like we got nowhere I was fiddling with things and re-enabled the policy that gave all the agents the same name and re-created the agent on the Security Console for that generic name.
This caused it to work again? The Technician mentioned that I may have been in the wrong for giving the agent name a IP in the earlier test. Not sure.
I am slowly rolling this out as we speak and the Windows Password Integration (WPI) does appear to be working.
Some other notes:
-WPI Is enabled on the Appliance (Authentication->Offline Authentication Policy). I did enable both the WPI and Offline Authentication. Previous Version did not need Offline Authentication
-The account that "Joins" the RSA Appliance to my AD Domain does not have admin privileges to the domain. Only Read rights. (RSA If you are reading this please update your documentation to state what permissions the appliance actually needs. I only found references to "Consult your windows admin".
-I am not using the cloud authentication products.
All,
If you've not already, please try:
Thank you, those are great suggestions and I did test those with the agent over the phone. All that was correctly enabled. We were not sure what eventually caused it to work. I would ask that the documentation get updated with more information about WPI and troubleshooting it.