How to exclude particular user from authentication manager we set up user group for the same but no luck.
After server restart it's still asking for RSA token we are unable to login with local admin as well.
Any help would be most appreciated.
Are you talking about the Windows Agent? Did you follow the GPO Template Guide (in the agent docs) to set the Local Access Settings? They will override settings made on the agent using the control center. It sounds like you've got "Challenge All Users" set by mistake.
The other possibility is that this is an older agent which always shows the RSA logo as part of the RSA Credential Provider on Windows.
The concept of challenged means the user needs a Passcode to authenticate, while an Un-Challenged user can logon with just a password. So if you setup a group for challenges, either Challenge everyone in the group, or challenge everyone Not in the group
On older agents or with then new agent on Windows 7, you will see an RSA logo for everyone
With Windows 10 and the newest Windows agent, you see Tiles. The point is that the user has to know if they need a Password or a Passcode, the agent should not and does not divulge that information as hackers could leverage it.
Retrieving data ...