• @chdafni-msft (Customer)​ ,

     

    Apologies, I am not sure why I didn't get a notification of your post until earlier this morning.

     

    In regards to Authentication Manager, the server can track what machines have an MFA Agent installed. If you look up the agent record in the Security Console and click on the context arrow next to the agent name, you will see an option for Agent Instances. Select this to view a page with information about the machines on which the MFA agent is installed.

     

    image 

     

    Additionally, there is a List All Installed Agents report template that you can run to see this information in a different format

     

    image 

    I hope this belated response answers your questions!

    Expand Post
    Selected as Best
  • @kamleshpatel87134 (Adani Enterprise Ltd)​ ,

     

    A list of all of your agents (PAM, Windows, etc.) can be found in the Security Console under Access > Authentication Agents > Manage Existing. If you are looking for RADIUS clients, navigate to RADIUS > RADIUS Clients > Manage Existing.

     

    Is there something in particular that you are looking for?

    • chdafni-msft (Customer)

      @EricaChalfin (RSA)​  - is this still true when using the latest Windows MFA Agent 2.3.1? As those agents are API driven / obtain their config from GPO, I don't believe they actually register with RSA AM - thus won't appear under "Access > Authentication Agents > Manage Existing". Please advise.

      • @chdafni-msft (Customer)​,

         

        With earlier agents (for example, Authentication Agent 7.4.x for Windows, Authentication Agent 8.1.3 for PAM, etc.), each one needs its' own agent record under Access > Authentication Agents > Manage Existing. An sdconf.rec needs to be placed on the agent and communication established by creating a node secret. The MFA agents that use REST do not implement the sdconf.rec and do not use a node secret. You can have the MFA agent installed on any number of machines with only one agent record listed in the Security Console. All you need to do is supply the agent with the correct RSA Authentication API REST URL when configuring that agent's GPOs.

         

        Expand Post
      • chdafni-msft (Customer)

        Hi @EricaChalfin (RSA)​  - here in lies the issue in terms of tracking agent installation - since RSA AM does not track agents w/ RSA MFA Agent, whereas the original RSA Authentication Agent did, is there a RSA specific mechanism for tracking/auditing where RSA MFA Agent is installed? Scenario: Identify where RSA MFA Agent is not installed or similar inventory for purposes of validating said systems will enforce MFA policies.

        This process was /automatic/ with the RSA Authentication Agent.

        Expand Post
      • @chdafni-msft (Customer)​ ,

         

        Apologies, I am not sure why I didn't get a notification of your post until earlier this morning.

         

        In regards to Authentication Manager, the server can track what machines have an MFA Agent installed. If you look up the agent record in the Security Console and click on the context arrow next to the agent name, you will see an option for Agent Instances. Select this to view a page with information about the machines on which the MFA agent is installed.

         

        image 

         

        Additionally, there is a List All Installed Agents report template that you can run to see this information in a different format

         

        image 

        I hope this belated response answers your questions!

        Expand Post
        Selected as Best
  • kamleshpatel87134 (Adani Enterprise Ltd)

    Hi Erica,

     

    Thanks for reply. Yor are correct for Radius & Authentication Agent (AD).

     

    But How we have to check only single RSAMFA Agent for Client machine.

     

    In my Company some time require to check latest version has updated in individual machine or not after install new version in Client machine by Local IT Team.

     

    Let me know if any having .

     

    Regards

    Kamlesh

     

     

     

    Expand Post
    • @kamleshpatel87134 (Adani Enterprise Ltd)​ ,

       

      We do not store the agent version information on the Authentication Manager server.

       

      What I can suggest is that you take inventory of your agents then navigate to Access > Authentication Agents > Manage Existing and edit the agent. You can use the Notes field to track the agent version information here. You can then run the List All Installed Agents report to track version information as you move forward.

       

      image

      Expand Post
  • kamleshpatel87134 (Adani Enterprise Ltd)

    Hi EricaChalfin,

     

    Thanks for reply its informative.