RSA Product Set: ID Plus
RSA Product/Service Type: MFA Agent for Windows
RSA Version/Condition: 2.3.5 and earlier
Windows OS/Patch:
Microsoft Windows 11 24H2 and later
Microsoft Windows Server 2022 and later
Microsoft Windows 11 24H2 upgrade (released in October 2024) and Windows Server 2022 introduced new features that do not allow RSA MFA Agent for Windows v2.3.5 and earlier to start.
If the Windows machine is running Windows 11 24H2 or Windows Server 2022, you will see the message below and the MFA Agent will no longer function on that machine.
Recent changes in the Microsoft Windows 11 24H2 and Windows Server 2022 Local Security Authority (LSA) process affect RSA MFA Agent for Windows v2.3.5 and earlier.
From RSA MFA Agent v2.3.6 onwards, the MFA Agent is fully compatible with the Local Security Authority (LSA) changes introduced in Windows 11 24H2 and Windows Server 2022. The issue does not occur. See AAWIN-7533 in section "Fixed Issues" on page 8 of the RSA MFA Agent 2.3.6 for Microsoft Windows Release Notes.
To fix this issue, RSA recommends installing or upgrading to the latest version of the RSA MFA Agent.
As a workaround on Windows 11 24H2 and Windows Server 2022 or later computers, until the MFA Agent can be upgraded to the latest RSA MFA Agent version, follow the steps below to disable Local Security Authority (LSA) and restore Agent functionality.
Disable Local Security Authority (LSA)
Steps to disable using Local Group Policy on Windows 11 version 24H2 and later:
- Open the Local Group Policy Editor by entering gpedit.msc.
- Expand Computer Configuration > Administrative Templates > System > Local Security Authority.
- Open the Configure LSASS to run as a protected process policy.
- Set the policy to Disable.
- Restart the machine
Microsoft reference: section "Disable LSA protection" on page https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#disable-lsa-protection
This issue has also been reported for the RSA Authentication Agent for Windows. That product has reached end-of-life, is no longer supported and has been replaced by the RSA MFA Agent for Windows (see section "Authentication Agents & Related SDK" on page Product Version Life Cycle for RSA ID Plus and RSA SecurID). Migration to the latest version of the RSA MFA Agent for Windows is strongly recommended.
Related Articles
Connecting to or querying the database using pgSQL in RSA Authentication Manager 8.x 1.78KNumber of Views Reporting Engine service is not running due to reportstatusmanager.h2.db corrupt 14Number of Views Webtier showing offline after hard shutdown. Error: System fingerprint encrypted key is missing and Failed to reload passw… 1.49KNumber of Views RSA Authentication Manager 8.8 upgrade fails with ERROR: auth_manager.rest_service.old_access_key is not found 1.85KNumber of Views Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … 1.18KNumber of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes for RSA Authentication Manager 8.8 RSA announces End of Life EOL dates for RSA MyAccessLive Service RSA Authentication Manager 8.9 Administrator's Guide