Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows is installed
Originally Published: 2020-01-08
Article Number
Applies To
RSA Product/Service Type: MFA Agent for Microsoft Windows
Issue
To disable this extra authentication step for a "Run as" scenario, perform the steps outlined below.
Resolution
Steps for accessing the GPO setting differ depending on whether or not GPO settings are managed by a domain controller or not. See the information below:
To access the GPO template on a Domain Controller:
- Click Start > Administrative Tools > Group Policy Management.
- If necessary, double-click the domain name in the left-hand frame to expand it.
- If necessary, double-click Group Policy Objects to expand it.
- Right-click the policy with the template you need to edit; for example, Default Domain Policy and click Edit.
- Double-click Policies from Computer Configuration.
- Double-click Administrative Templates: Policy definitions (ADMX files).
- Double-click RSA Desktop.
- Click on Local Authentication Settings.
- Follow instructions below to complete the task.
To access the GPO Template directly on MFA Agent machine:
- Click Start > Run > gpedit.msc.
- Double-click Administrative Templates.
- Double-click RSA Desktop.
- Click on Local Authentication Settings.
- Follow instructions below to complete the task.
For either option,
- Once inside Local Authentication Settings, double click Specify Remote Desktop Applications that Do Not Require RSA SecurID.
- Enable the setting and then add C:\Windows\explorer.exe to the list of Fully-Qualified Application Path(s) within the setting.
Notes
If this setting is enabled and the default RDP behavior is desired, then "C:\Windows\System32\CredentialUIBroker.exe" or "C:\Windows\System32\mstsc.exe" (depending on the Windows version) must be explicitly added to the list of Fully-Qualified Application Path(s) within the policy setting.
Related Articles
Troubleshooting RSA MFA Agent for Microsoft Windows 4.28KNumber of Views RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide 1.72KNumber of Views RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide 800Number of Views Enable a web proxy for RSA MFA Agent for Microsoft Windows 475Number of Views Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory 838Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Authenticator 6.2.2 for Windows Administrator Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows
Don't see what you're looking for?