RSA Product/Service Type: Authentication Manager & MFA Agent for Microsoft Windows
RSA Version: 8.7 SP1 and above (Authentication Manager) & 2.2.1 and above (MFA Agent for Microsoft Windows)
Windows password retrieval failed
Agent <Agent Name> is unable to retrieve Windows password for user <UserID>
JWT token has expired.
The time is not in sync between the Authentication Manager server(s) and the machine the MFA Agent for Windows is installed on.
Correct the time between the Authentication Manager server(s) and the machine the MFA Agent for Windows is installed on.
If the time on any of the Authentication Manager server(s) needs to be adjusted and is off by more than a couple of minutes, contact RSA Customer Support for assistance before proceeding. See the "Update System Date and Time Settings" page if adjusting the time on the Authentication Manager server(s) is needed.
----------------------------------------------------------------------------------------------------------------
Correcting the time between the Authentication Manager server(s) and machine the MFA Agent for Windows is installed on should typically resolve this issue, but if it does not, then there is a command line utility that can be run from the Primary Authentication Manager server to increase the time skew allowed between the server and agent machines. To run this command:
1. Log into the command line of the Primary Authentication Manager server.
2. Run the following command: /opt/rsa/am/utils/rsautil store -a update_config auth_manager.agent.max_clock_skew.seconds <skew allowed in seconds> <Primary Authentication Manager FQDN>
Note: The default "skew allowed in seconds" is 5.
Related Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device 903Number of Views RSA MFA Agent for Windows will not run due to error "This module is blocked from loading into the Local Security Authority" 855Number of Views RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows 2.04KNumber of Views RSA Authentication Manager 8.8 upgrade fails with ERROR: auth_manager.rest_service.old_access_key is not found 2.36KNumber of Views RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.25KNumber of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Release Notes: Cloud Access Service and Authenticators