Identity Sources for Self-Service Users
The identity source where the users’ accounts are stored affects which actions users can perform using the Self-Service Console. You can use the internal database, Active Directory, Oracle Directory Server, and OpenLDAP as identity sources.
If an Active Directory, Oracle Directory Server, or OpenLDAP has the “change password during next logon” option set, you cannot enroll users in Self-Service.
Using the Internal Database as an Identity Source
AM can read and write data to the internal database. Users whose accounts are in the internal database can use the Self-Service Console to perform all actions for which their administrator has configured permissions. For example, these actions may include resetting passwords or entering phone numbers or e-mail addresses on the Identity Confirmation Method configuration page for on-demand authentication with risk-based authentication (RBA).
Using Active Directory as an Identity Source
Users whose accounts are in Active Directory cannot use the Self-Service Console to perform any actions that require AM to access Active Directory. For example, users whose accounts are stored in Active Directory cannot use the Self-Service Console to change their Self-Service passwords. AM has read-only access to Active Directory for all user and user group data.
Using Oracle Directory Server as an Identity Source
Users whose accounts are in Oracle Directory Server cannot use the Self-Service Console to perform any actions that require AM to access Oracle Directory Server. AM has read-only access to Oracle Directory Server for all user and user group data.
Using OpenLDAP as an Identity Source
Users whose accounts are in OpenLDAP cannot use the Self-Service Console to perform any actions that require AM to access OpenLDAP. AM has read-only access to OpenLDAP for all user and user group data.
Related Tasks
Related Articles
Active Directory Identity Sources that are Not Global Catalogs 13Number of Views Unlink Identity Sources from the System 126Number of Views Active Directory Global Catalog Identity Sources 83Number of Views Identity Source Properties 123Number of Views "Error creating the Create New Authentication Source" is thrown when trying to add or edit an Authentication Source in RSA… 59Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start'