There are two connections between Cloud Authentication Service and RSA Authentication Manager, i.e "Connection to Authentication Manager" and "Connection from Authentication Manager".
User has an MFA registered on CAS, but no MFA token registration on Authentication Manager yet. User fatfingers/submits an incorrect Authenticate token code, User Event Monitor captures two failure messages on Cloud Authentication Service for one unsuccessful identity router authentication attempt. These attempts are counted twice against the lockout count resulting in Cloud Authentication user profile lockouts on RSA Authentication Manager.
Login to the primary Authentication Manager server as rsaadmin and enter the operating system password.
Note that during Quick Setup another username may have been selected. Use that username to login.
Navigate to /opt/rsa/am/utils.
Run the following command line utility (CLU) to add the authentication agent name:
./rsautil store -a add_config auth_manager.cas.authentication.runtime.skip.agentnames "<Agent name>" GLOBAL STRING
login as: rsaadmin
Using keyboard-interactive authentication.
Last login: Tue Jun 05 07:52:43 2021 from 192.168.20.100
RSA Authentication Manager Installation Directory: /opt/rsa/am
rsaadmin@am85p:~> cd /opt/rsa/am/utils
rsaadmin@am85p:/opt/rsa/am/utils> ./rsautil store -a add_config auth_manager.cas.authentication.runtime.skip.agentnames "cas2am" GLOBAL STRING
Please enter OC Administrator username: ocadmin
Please enter OC Administrator password: ********
psql.bin:/tmp/cd192016-7ab2-41c1-b001-0c012fe1a7873828816399055336931.sql:108: NOTICE: Added the new configuration parameter "auth_manager.cas.authentication.runtime.skip.agentnames" with the value "cas2am"
To update the authentication agent name, run the following command: ./rsautil store -a update_config auth_manager.cas.authentication.runtime.skip.agentnames "<Agent name>" GLOBAL STRING