This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Knowledge Base

Find answers to your questions and identify resolutions for known issues with knowledge base articles written by SecurID experts.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Knowledge Base
  • :
  • Send both user name and domain name to the server during an RSA Authentication Agent for Windows aut...
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Send both user name and domain name to the server during an RSA Authentication Agent for Windows authentication request

Article Number

000013708

Applies To

RSA Product Set:  SecurID
RSA Product/Service Type:  RSA Authentication Agent for Windows
RSA Version/Condition:  7.1

 

Issue

  • This article explains how to send both user name and domain name to the server during an RSA Authentication Agent for Windows authentication request
  • Agent processing of NTLM name mapping

Resolution

The RSA Authentication Agent for Windows can accept logins from users in the formats of username, username@domain and domain\username.  However, by default, it will remove the domain name, and send just the username to the Authentication Manager server.  The agent has a checkbox labeled Send the domain name and user name to RSA Authentication Manager instead of just the user name.  If this is checked, it will send a request in a format similar to domain\username.

However, it can do some normalization of the request.   With the RSA Authentication Agent 7.2.1 for Windows:
  • domain\username.  The agent will case-normalize the domain name to uppercase. It does not try to case-normalize the username.  For example,  Username@Domain becomes DOMAIN\Username.
  • username@domain.  The agent case-normalizes the user name to lowercase. It does not try to case-normalize the domain name.   An example is Username@Domain becomes Domain\username.

Notes

The RSA Authentication Manager server can be configured to use email addresses to identify users in an identity source, instead of using the default samAccountName. This would require an authentication request to be send in the form of user@domain, but the agent does not send in that format.

Authentication Manager can be configured to map a NTLM name (DOMAIN\username) to a UPN (user@domain) with NTLM mappings, to allow resolving the username.  See the article on how to authenticate to an RSA Authentication Agent for Windows as user@domain.com with NTLM to UPN name mapping for more information on NTLM to UPN name mapping.
 
Tags (28)
  • 7
  • 7.1
  • 7.1.x
  • 7.x
  • Agent
  • Auth Agent
  • Authentication Agent
  • Customer Support Article
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Microsoft
  • Microsoft Windows
  • Microsoft Windows Agent
  • RSA SecurID
  • RSA SecurID Access
  • RSA SecurID Suite
  • SecurID
  • SecurID Access
  • SecurID Agent
  • SecurID Suite
  • Version 7
  • Version 7.1
  • Version 7.1.x
  • Version 7.x
  • Windows
  • Windows Agent
  • Windows Authentication Agent
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2020-12-13 12:21 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.