Troubleshooting guide

1: Important RSA Authentication Manager 8.1 Changes 25
RSA Authentication Manager 6.1 to 8.1 Migration Guide
You can create user groups through the Security Console, or for external data sources
such as Active Directory, using the directory user interface.
Version 8.1 does not permit you to scope administrators to user groups.
Administrative control of groups is defined by the security domain in which the group
resides, and not by administrative scoping to the group, as in version 6.1.
For example, version 6.1 groups that do not belong to a site are migrated to the
top-level security domain, which is managed by the Super Admin. If your groups
belong to a site, the groups are migrated to the lower-level security domain created for
the migrated site. The site administrator, who is the administrator of the lower-level
security domain, controls the lower-level security domain.
Migrating User and User Group Activation on Agents
Version 8.1 supports the activation of groups on authentication agents. However,
version 8.1 does not support individual user activation on agents. Because you can no
longer activate individual users on agents, migration uses group activations to
maintain a similar behavior.
Note: In version 8.1, you should only associate a user group with an unrestricted agent
when you want to enable the use of logon aliases. Users cannot authenticate with an
alias on a restricted or unrestricted agent without belonging to the user group that is
associated with the logon alias.
The following table describes the effect that migration has on groups activated on
agents.
Pre-Migration Post-Migration
Group activated with access time
restrictions
The group is migrated with access time restrictions;
however, the time restrictions are only activated on a
user group that is associated with a restricted agent. In
version 8.1, access time restrictions only apply to
restricted agents.
The migrated group name has the following format:
AM61_useraceIDofUserGroup_FQDNofagent_ISname
The agent remains restricted or unrestricted. Group
associations to agents are migrated. All associated
logon aliases are also migrated.
Group activated with no access
time restrictions
The group is migrated with no access time restrictions.
The group name has the following format:
Agent_Name
The agent remains restricted or unrestricted. Group
associations to agents are migrated. All associated
logon aliases are also migrated.