How to prevent a local administrator from setting a reserve password in the RSA Authentication Agent for Windows Control Center
Originally Published: 2019-10-14
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4
Issue
This ability raises two questions:
- Is there a way to prevent this, either via GPO that disables Reserve Passwords or with a Windows Security Policy?
- Would the administrator still have the ability to enable and set a Reserve Password in the registry or through Windows Local Security Policy, so that the local administrator cannot be prevented from bypassing the passcode challenge with a Reserve Password they created?
Tasks
Resolution
The domain policy can set a totally bogus Reserve Password if all you want to do is to block users from setting their own.
Alternatively, you could set a reserve password in the domain policy that only certain Authentication Manager administrators know. This password can be changed periodically to ensure its' security.
Notes
If users have administrative privileges, pushing out domain policies is probably a generally good practice for maintaining control, even for policies for which the default agent behavior is the behavior that you want.
For example, the agent disables the Microsoft Password Provider by default, but provides a filter GPO that allows an administrator to change that. Customers should probably push out a domain policy that also prevents an administrative user from changing that.
Related Articles
Administrator is able to change a user password in RSA ACE/Server even though it is not allowed in his task list 3Number of Views RSA-2024-13: RSA Authentication Agent for Microsoft Windows Security Update 243Number of Views Supported operating systems for the RSA SecurID Authentication Agent 8.1 for PAM 128Number of Views RSA Authentication Manager 8.2 SP1 Vulnerabilities in Mozilla Firefox -false positive 34Number of Views Running AFX Connectors start to fail, edited connectors remain in a Not Deployed state and 'Could not connect to broker UR… 591Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?