Hello together,
I am using RSA Authentication Manager 8.5 P1 for MFA.
The userbase is imported by LDAP from a Microsoft Active Directory.
Now when a user leaves the company and gets disabled in AD, the user also becomes disabled in RSA.
Is there a way to also automatically unassign a user's SecurID token on the event of disabling the user, or after a specific time of being in disabled state?
Thank you very much in advance.
Best regards,
Niklas
When you disable a user in AD, do you also disable the account in Authentication Manager? When an auth request arrives, if the user record is in AD, AM will check the AD enable flag and/or the AM enable flag, depending on the settings for that identity source. There's nothing in AM that automatically disables the user on the AM side when the user is disabled in AD.
That said, are you 100% certain that a user account is never disabled for any reason other than leaving the company? You don't disable an account if they take extended leave, for instance?