This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Knowledge Base

Find answers to your questions and identify resolutions for known issues with knowledge base articles written by SecurID experts.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Knowledge Base
  • :
  • Migrating users across identity sources in RSA Authentication Manager 8.x
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Migrating users across identity sources in RSA Authentication Manager 8.x

Article Number

000026361

Applies To

RSA Product Set:  SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x

Issue

This article provides information on:
  • How to move users with tokens from one identity source to another, and
  • How to merge users with tokens from one external identity source into another external identity source,

Resolution

Be sure to take a backup of the database or a snapshot of the virtual server before continuing.

To import the users that were exported from one external identity source to another, the users' first name, last name, and default login must all match on both Active Directory servers.  Please confirm this before continuing.


In the example below there are ten users named test1 - test10 that are housed in an external Active Directory identity source that is on a Windows 2003 Server.  All ten users have tokens assigned and PINs have been created.  One of the users also has a replacement token assigned, but has not used it yet.

  1. To make things easier a group named export has been created in the Authentication Manager Security Console (Identity > User Groups > Add New).  Users test1 - test10 have been assigned to the group by clicking on the context arrow next to the group name and choosing Member Users.  Search for user and when results come back select them and click Add User to Group.  It is possible to just export all users with tokens as well.
  2. To export the users, first download the encryption key by selecting Administration > Export/ Import Tokens and Users > Download Encryption Key and save the file to a desired location.
  3. Now export the users by selecting Administration > Import/Export Tokens and Users > Export Tokens and Users.
  4. Browse to the encryption key downloaded in step 2 and select Users with Tokens (Users without tokens will not be exported) for the Export Type and click Next.
  5. On the next screen under Filter User with Tokens By Group, select Narrow the selection by group membership.  Enter the name of the group created in step 1 which has the desired users and hit Search.
  6. Select the group and then press > to bring the group over on the right side under the Selected Groups section.
  7. Check the box next to the group and click Export.
  8. This brings up the Import/Export Status screen.  Once it is complete, download the file.  Save the file in the same directory where the encryption file was saved in step 2.
  9. Now remove the users that have been exported and cleanup the database. If all the users have been exported, the identity source can be unlinked in the Security Console under Setup > Identity Sources > Link Identity Source to System. Unlink the identity source and click Save.
  10. Confirm that you want to unlink the identity source on the subsequent screen and make sure to check the box, then click on Unlink.
  11. Run the scheduled cleanup job (Setup > Identity Sources > Scheduled Cleanup), setting the job to run a few minutes ahead of the current time and click Save.  
  12. Monitor the progress using the real-time system monitor (Reporting > Real Time Activity Monitors > System Activity) or under Administration Batch Jobs.  
  13. Once the cleanup is complete,  login to the Operations Console and delete the Identity Source you just unlinked by selecting Deployment Configuration > Identity Sources > Manage Existing.  Click on the context arrow next to the correct identity source and select Delete.
  14. On the following screen check the box for Yes, delete the identity source and click Delete Identity Source.
  15. To import the users that were exported from the AD on the Windows 2003 Server into a 2008 domain, the first name, last name, and default login must all match what is on the Windows 2008 server.  The Windows 2008 Server identity source is already setup in Authentication Manager 8.1 and linked via the Security Console.
  16. Import the users that were exported by selecting Administration > Import/Export Tokens and Users > Import Tokens and Users.
  17. Select the .pkg file that was  created during step 8 of the export and click Next.
  18. Edit the system domain, if needed, or keep the default of System Domain and click Next.
  19. On the subsequent screen select the identity source into which you are importing your users and tokens and click Next.
  20. When done, an export/import status screen will show.
  21. Review the summary which should match the export summary and click Import.  Note that it is possible to see a Done with Warning status as well. This is just the unassigned token records being overwritten.
  22. The imported users should now show up in the new identity source with their tokens and PINs intact.

To see these steps with screenshots included, see the attached pdf.

Attachments
Tags (91)
  • 8
  • 8.0
  • 8.0.x
  • 8.1
  • 8.1.x
  • 8.2
  • 8.2.x
  • 8.3
  • 8.3.x
  • 8.4
  • 8.4.x
  • 8.x
  • Admin
  • Admin Tutorial
  • Administration
  • Administrative
  • AM
  • Appliance
  • Auth Manager
  • Authentication Manager
  • Best Practice
  • Best Practices
  • Config
  • Configuration
  • Configure
  • Configuring
  • Customer Support Article
  • Delete Software
  • Helpful Hints
  • How To
  • Implementation
  • Implementing
  • Informational
  • Install
  • Install Process
  • Install Steps
  • Installation
  • Installation Process
  • Installing
  • Instructions
  • Integrate
  • Integrated
  • Integrating
  • Integration
  • Integration Steps
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • management
  • Process Steps
  • Product Install
  • Product Integration
  • Recommendations
  • Recommended
  • Recommended Practice
  • Remove Software
  • RSA AM
  • RSA Auth Manager
  • RSA Authentication Manager
  • RSA SecurID
  • RSA SecurID Access
  • RSA SecurID Suite
  • SecurID
  • SecurID Access
  • SecurID Appliance
  • SecurID Suite
  • Set Up
  • Setup
  • Software Removal
  • Tip &amp Tricks
  • Tips and Tricks
  • Tutorial
  • Un-install
  • Uninstall
  • Uninstall Software
  • Uninstallation
  • Uninstalling
  • Version 8
  • Version 8.0
  • Version 8.0.x
  • Version 8.1
  • Version 8.1.x
  • Version 8.2
  • Version 8.2.x
  • Version 8.3
  • Version 8.3.x
  • Version 8.4
  • Version 8.4.x
  • Version 8.x
  • Walk Through
  • Walkthrough
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2021-04-23 05:59 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.