- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I challenge all users except my .\Administrator (local admin)?
I want my agents to challenge all users except my Local Administrator on each box. I know that I can challenge all users except the Administrator Group but our group policy has Domain.com/Domain Administrators in each Local Administrators group. Because of this, I can still log on with my Domain Admin account without being challenged. However, at our other site, it works as desired. Group policy matches at both sites. Both sites use active directory for user acct's and groups. What am I missing? Why does Site 1 challenge all users except Local Admin and Site 2 challenges all users except Local and Domain Admins?
- Tags:
- active directory identity source
- administrators
- Agent
- Agents
- Auth Agent
- authenticaion manager
- Authentication Agent
- challenge all except
- Community Thread
- Discussion
- Forum Thread
- group policy
- rsa authentication agent 7.4.3
- RSA SecurID
- RSA SecurID Access
- SecurID
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This needs additional details and verbose logs from the agent side to check about the user group enumeration during the process of authentication.
Ensure that when you do tests on Site1 and Site2, you are running the latest version of RSA Windows Agent
https://community.rsa.com/docs/DOC-106864
Kindly open a case for further review and investigation. Refer 000036161 - How to open a technical support case via the Case Management portal on RSA Link.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm looking for a Group Policy or settings fix here, not to build another AD group.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This needs additional details and verbose logs from the agent side to check about the user group enumeration during the process of authentication.
Ensure that when you do tests on Site1 and Site2, you are running the latest version of RSA Windows Agent
https://community.rsa.com/docs/DOC-106864
Kindly open a case for further review and investigation. Refer 000036161 - How to open a technical support case via the Case Management portal on RSA Link.
-Sri
