How to authenticate to an RSA Authentication Agent for Windows as user@domain.com with NTLM to UPN name mapping
Originally Published: 2010-10-12
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Agent for Windows
RSA Version/Condition: 7.x, 8.x
Issue
Is there any way to have the company.com\name automatically recognized by RSA as name@company.com without making an alias?
- All users in the RSA Authentication Manager database are listed as username@company.com. The authentication agent sends either the username only, or company.com/username and no one authenticates.
- Authentication activity monitor reports userid or alias not found.
- Administrators cannot use aliases.
Resolution
On the Windows machine hosting the RSA Authentication Agent the Send Domain Name option is checked.
- Login to the Security Console on the primary Authentication Manager server.
- Select Setup > System Settings.
- Under Authentication settings click Agents.
- Scroll to the bottom of the page for the section on Domain Name Mapping.
- Fill out the NTLM box with company.com and UPN box with company.com.
For long domains such as domain1.domain2.company.com, you may only need to put domain1 in the NTLM box and not domain1.domain2.
- Click Save.
- Now test authentication with the real time authentication activity monitor open. The Authentication Manager server will translate the incoming authentications at the agent and the user is able to authenticate with the user ID of name@company.com and passcode. The Authentication Manager server receives company.com/name which doesn't actually exist and it automatically translates to name@company.com and authenticates.
If authentications do not work and login failures appear, watch the real-time authentication activity log. It should clearly show the translated names and indicate if there is something missing or added to the name and you can adjust the settings you chose above and try again until it matches your environment.
Related Articles
Send both user name and domain name to the server during an RSA Authentication Agent for Windows authentication request 177Number of Views Users cannot authenticate with login name in domain\sAMAccountName format using MFA Agent 2.0.1 76Number of Views Unchallenged Active Directory users fail to authenticate with RSA Authentication Agent for PAM 284Number of Views RSA Authentication Agent 7.2.1 for Windows cannot determine challenge group if the user submits fully qualified domain nam… 217Number of Views 'Request could not be handled' and 'No enum constant com.aveksa.server.core.DataCollector.Status.InActive' errors exportin… 156Number of Views
Trending Articles
RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?