RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
After following the steps outlined in the RSA integration guide and configuring SailPoint IdentityIQ to connect with the RSA Authentication Manager API, the following error appears when testing the connection:
"Could not find the realm: SystemDomain"
The error occurs because the RSA Administrator username entered during the SailPoint IdentityIQ configuration does not have sufficient permissions to view Security Domains in RSA Authentication Manager.
This user account is managed through the Security Console, and it must have at least the View permission under Manage Security Domains in their admin's role as shown below:
If the account lacks this permission, it will be unable to retrieve realm details, resulting in the following error when testing the connection:
Could not find the realm: SystemDomain
Granting View access to Security Domains resolves the issue. Assigning broader permissions such as Super Admin is not required.
For steps on how to assign admin roles in RSA Authentication Manager, refer to Add an Administrative Role | RSA Community
The screenshot below shows the administrator account entered in SailPoint IdentityIQ referenced above
To resolve this issue, ensure that the administrator account used in the SailPoint IdentityIQ configuration has permission to view Security Domains in RSA Authentication Manager.
- In the Security Console, click Administration > Administrative Roles > Add New.
-
Under the General Permissions tab, locate the Manage Security Domains section.
-
Enable the View permission for Security Domains.
This level of access should be sufficient to allow IdentityIQ to retrieve realm information.
For detailed steps on how to add or modify an admin role in RSA, refer to the official RSA documentation:
Add an Administrative Role | RSA Community
Related Articles
Aserver error message on startup 'The system cannot find the path specified' 27Number of Views Error when running RSA Via Lifecycle & Governance 7.0 customizeACM.sh: Could not find Aveksa ear 238Number of Views AAOP - Scheduler SP3P1 on Weblogic 10.3 deployment issue->Cannot find the declaration of element 'beans'. 19Number of Views How to use Microsoft Windows Powershell to find the checksum values of RSA Authentication Manager files 170Number of Views SailPoint IdentityIQ 8.1 - SecurID Access Implementation Guide 68Number of Views
Trending Articles
RSA Authentication Manager Patch Updates RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Configuring a Checkpoint firewall to work with SecurID