Just-in-time synchronization failed - unable to contact directory server with RSA Cloud Authentication Service (CAS)
Originally Published: 2025-06-19
Article Number
Applies To
RSA Product Set: RSA ID Plus
RSA Product/Service Type: RSA Cloud Authentication Service
Version(s): All supported versions
Issue
Users fail to authenticate and the following error in the user event monitor:
Jut-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Unable to contact directory server.
Cause
The cause is the connection between the Cloud Administration Console and the Active Directory is failing. This could be caused by various reasons, but few of the most popular reasons are:
- The account used in the LDAP binding is expired, disabled, locked, or its password has been expired or changed.
- If you are using LDAPS, the SSL certificate might be the issue if it was expired or changed on the Active Directory.
- The identity router might be distressed or down.
- A network issue.
- A configuration issue.
In this article we will focus on fixing the binding account issue and the SSL certificate.
Resolution
To begin,
- Log in to your Cloud Administration Console.
- Go to User > Identity Sources.
- Click on Edit for the identity source that is having a problem.
- In the Identity Source Details section go down to:
- Directory servers:
- In the table that contains all the domain controllers listed for this Active Directory, edit each connection to change the binding account or its password.
- The edit button is a pencil shaped icon.
- SSL/TLS Certificates:
- If the certificate is missing, expired, or you just need to change it, you can change it in this section.
- Directory servers:
- After doing the needed changes keep clicking on Next Step then Save and Finish.
- Publish Changes to apply the changes that you made.
- Try to authenticate again or manually sync the users.
Notes
If that didn't help fixing you issue, please contact RSA Technical Support for assistance.
Related Articles
enVision: how to specify just one collector using lsdata 48Number of Views FIM - Log4j memory leak 27Number of Views The audit.log is not logging to the proper location defined in the log4j.xml 23Number of Views RSA Customer Advisory: Apache Vulnerability Log4j2 CVE-2021-44228 170Number of Views Old connector Log4j files not removed in RSA Governance & Lifecycle 48Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM
Don't see what you're looking for?