AnsweredAssumed Answered

What is the process for the RSA Authentication Agent for Microsoft Windows to update its list of Authentication Manager servers during a server migration?

Question asked by Lenore Tumey Employee on Jul 24, 2019
Latest reply on Aug 16, 2019 by Steven Spicer

I was talking with a customer yesterday who is migrating all of their AM servers to Amazon Web Services.  Their process involves adding new replicas in AWS, then promoting one of them to become the primary, and then shutting down the original (on-prem) AM servers. 


They have a lot of Windows clients using the RSA Authentication Agent for Microsoft Windows (a.k.a. “Local Authentication Client”/LAC) agent to protect desktop logins, and had some questions about how those agents get updates regarding which AM servers exist.


  1. Should the LAC agent automatically pick up changes to the available AM servers, and if so, is this done as part of an authentication request processing, and/or at any other time (such as at Windows reboot time)? 
  2. Does the LAC agent use Contact Lists (, and/or a different mechanism?  
  3. Is there an easy way to see if the new AM servers are being detected by the client (such as by looking at the client's files - perhaps failover.dat, sdconf.rec, sdstatus.12, or securid files?)
  4. Does the customer need to push out an updated sdconf.rec file to all clients during or after the server migration?