RSA Product Set: SecurID
RSA Product/Service Type: MFA Agent for Windows
RSA Version/Condition: 2.4 and later
For Microsoft Entra ID joined devices, agent settings can be configured using the file generated below. Agent configuration settings for Microsoft Entra ID joined devices are not set through GPO settings.
The RSA_MFA_Agent_Config_Utility_For_Microsoft_Entra_ID.exe creates a template text file which contains the key-value pairs needed
for the RSA MFA Agent.
To resolve this issue,
- Make a backup of the original RSA_MFA_Agent_Config.txt.
- Edit the RSA_MFA_Agent_Config.txt to what is shown below:
########################### Disable RSA authentication for unknown user ###########################
##### Help:
##### If you are using RSA during Windows authentication,
##### this config key specifies if the Agent allows a user unknown to RSA to sign in with only a
##### Windows password.
##### Users are unknown to RSA when they do not exist in an RSA identity source.
##### If you enable this config key, then the Agent allows unknown users to sign in with only a
##### Windows password and not require additional or passwordless authentication.
##### If you do not configure or disable this config key,
##### then the Agent does not allow unknown users to sign into their computers.
##### Options:
##### DisableMfaUnknownUser=0 (Allow unknown user) OR
##### DisableMfaUnknownUser=1 (Not allow unknown user)
##### If Enabled=0, whole key will be ignored
Enabled=1
##### Must be reset to 0 if Enabled is set
DisableMfaUnknownUser=1
############################################# ENDKEY ##############################################
- Save and close the file.
Related Articles
Configure Microsoft Entra ID Joined Devices for RSA MFA Agent for Windows 259Number of Views Configure Microsoft Entra ID Joined Devices for RSA MFA Agent 2.4 for Windows 94Number of Views Configure Active Directory Joined Devices for RSA MFA Agent 2.4 or Later for Windows 15Number of Views Microsoft Entra ID - SCIM Client for Cloud Authentication Service - RSA Ready Implementation Guide 533Number of Views Microsoft Entra ID - RSA Ready Implementation Guide 247Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Reset the token PIN in the RSA Authentication Manager 8.x Self-Service Console when the existing PIN is forgotten RSA-2026-05: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities RSA Release Notes: Cloud Access Service and RSA Authenticators