Disable offline day downloads yet run offline local Sservice for RSA Authentication Agent 7.2.1 for Windows
Originally Published: 2015-04-20
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.2.1
Issue
Use case
- During a load test of RSA Authentication Agent 7.2.1 for Windows build 73 (7.2.1.73), logon errors started happening after 30 RDP users connected to the Windows server.
- The server is always LAN connected; therefore, the users who connect to this server never need Offline Authentication download days.
- Users would like to use Windows Password Integration, which uses the RSA Authentication Agent Offline Local Service (to TCP port 5580 on the RSA Authentication Manager server).
- The download of offline days appears to be slowing down the Windows server, preventing some users from connecting and authenticating (typically the 31st user).
- Admins would like to disable the downloading of offline days on the server, but leave the Offline Local Auth service running in case a user needs to change/update their Windows password.
Tasks
- Delete the InstallDir registry string from HKEY_LOCAL_MACHINE\SOFTWARE\RSA\RSA Desktop Common\Disconnected Authentication\ in the Windows Registry.
- Upgrade to the latest RSA Authentication Agent 7.4.3 for Windows (latest release as of 9 January 2020).
- (The latest windows agent is available on RSA LINK web site
Resolution
- From Start, type regedit to open the Registry Editor.
- Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\RSA\RSA Desktop Common\Disconnected Authentication\.
- Delete the InstallDir registry string.
Notes
If one only needs to retrieve the password from the server as the user logs in, then one does not need the Offline Authentication Service. (AceGetLoginPW() retrieves the password from the sSUSER structure's loginPW member). However, if one also needs to support updating the password on the RSA Authentication Manager server, then one needs to communicate with the Offline Authentication Service (AceSetLoginPW() invokes AceDASetLoginPW() to set the password through the Offline Authentication Service).
Related Articles
Offline Authentication Policy 322Number of Views Troubleshooting failed offline authentication on an RSA Authentication Agent 7.3 or 7.4 for Windows 904Number of Views Offline Authentication 146Number of Views Portal Multifactor Authentication Policy 34Number of Views View a Risk-Based Authentication Policy 3Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM
Don't see what you're looking for?