Allow a User Group to Authenticate on anAgent
Use the following procedure to allow a user group to authenticate on a restricted agent or to enable the use of logon aliases on a restricted or unrestricted agent.
Restricted agents process authentication requests only from users who are members of user groups that have been granted access to the restricted agent. Users who are not members of an associated user group cannot use the restricted agent to authenticate.
Using restricted agents increases your control over who can authenticate to a resource. However, using restricted agents also increases your administrative overhead because administrators must explicitly associate user groups with the agents.
To authenticate on a restricted or unrestricted agent with a logon alias, a user must belong to a user group that is associated with the logon alias and that is enabled for authentication on the agent.
Procedure
In the Security Console, click Access > Authentication Agents > Manage Existing.
Click the Restrictedor Unrestricted tab.
Use the search fields to find the agents to which you want to grant access or enablelogon aliases.
Select the checkbox next to the agents to which you want to grant access or enable logon aliases.
Do one of the following:
For restricted agents, select Grant Access to User Groups from the Action menu, and click Go.
For unrestricted agents, select Enable Logon Aliases from the Action menu, and click Go.
Use the search fields to find the user groups to which you want to grant access or enable logon aliases.
Select the checkbox next to the user groups to which you want to grant agent access or enable logon aliases.
Do one of the following:
For restricted agents, click Grant Access to User Groups.
For unrestricted agents, click Enable Aliases Associated with User Groups.
Related Concepts
Related Articles
Allow Users to Authenticate on an Agent 23Number of Views Allow a User to Authenticate Without an RSA SecurID PIN 52Number of Views To allow automatic vetting of Sentry CA 3R1-3R4 certificate requests. 2Number of Views Allow Trusted Users to Authenticate Using RSA RADIUS 9Number of Views Users cannot authenticate with login name in domain\sAMAccountName format using MFA Agent 2.0.1 76Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)