This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Discussions
  • :
  • How can I challenge all users except my .\Administrator (local admin)?
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page
EverettCulberts
EverettCulberts Beginner
Beginner
‎2019-11-22 11:35 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

How can I challenge all users except my .\Administrator (local admin)?

Jump to solution

I want my agents to challenge all users except my Local Administrator on each box.  I know that I can challenge all users except the Administrator Group but our group policy has Domain.com/Domain Administrators in each Local Administrators group.  Because of this, I can still log on with my Domain Admin account without being challenged.  However, at our other site, it works as desired.  Group policy matches at both sites.  Both sites use active directory for user acct's and groups.  What am I missing?  Why does Site 1 challenge all users except Local Admin and Site 2 challenges all users except Local and Domain Admins?

Labels (1)
Labels
  • Labels:
  • Agents

  • Tags:
  • active directory identity source
  • administrators
  • Agent
  • Agents
  • Auth Agent
  • authenticaion manager
  • Authentication Agent
  • challenge all except
  • Community Thread
  • Discussion
  • Forum Thread
  • group policy
  • rsa authentication agent 7.4.3
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
1 Solution

Accepted Solutions
SrirangaPrasan1
Employee SrirangaPrasan1
Employee
In response to EverettCulberts
‎2019-11-27 05:00 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Jump to solution

This needs additional details and verbose logs from the agent side to check about the user group enumeration during the process of authentication.

Ensure that when you do tests on Site1 and Site2, you are running the latest version of RSA Windows Agent

https://community.rsa.com/docs/DOC-106864 

 

Kindly open a case for further review and investigation. Refer 000036161 - How to open a technical support case via the Case Management portal on RSA Link.

 

-Sri

View solution in original post

0 Likes
Share
Reply
2 Replies
EverettCulberts
EverettCulberts Beginner
Beginner
‎2019-11-22 11:37 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Jump to solution

I'm looking for a Group Policy or settings fix here, not to build another AD group. 

0 Likes
Share
Reply
SrirangaPrasan1
Employee SrirangaPrasan1
Employee
In response to EverettCulberts
‎2019-11-27 05:00 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Jump to solution

This needs additional details and verbose logs from the agent side to check about the user group enumeration during the process of authentication.

Ensure that when you do tests on Site1 and Site2, you are running the latest version of RSA Windows Agent

https://community.rsa.com/docs/DOC-106864 

 

Kindly open a case for further review and investigation. Refer 000036161 - How to open a technical support case via the Case Management portal on RSA Link.

 

-Sri

0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.