Challenge Users

Defines the users that Authentication Agent challenges for RSA SecurID credentials. You can challenge all users, all users except those in a specified group, only users in a specified group, or no users. You can specify whether or not to send the domain name and user name to RSA Authentication Manager instead of just the user name.

Note: If you challenge only users in a specified group or all users except those in a specified group, you must enter the name of the group in the Group name field. Enter the group name in the format \, or for the current machine, enter .\. You must enter a valid group name. If the group name is invalid or does not exist, Authentication Agent challenges all users.

Supported on: Supported on Windows 7 or later.

Enable policy:
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
Value NameEnableChallenge
Value TypeREG_DWORD
Value1
Disable Policy:
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
Value NameEnableChallenge
Value TypeREG_DWORD
Value0

Select the users to challenge.

Challenge:


  1. Off
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
    Value NameChallengeMode
    Value TypeREG_DWORD
    Value0
  2. Users in
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
    Value NameChallengeMode
    Value TypeREG_DWORD
    Value1
  3. All users
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
    Value NameChallengeMode
    Value TypeREG_DWORD
    Value2
  4. All users except
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
    Value NameChallengeMode
    Value TypeREG_DWORD
    Value3

Enter the name of the challenge group in the format

<domain name or machine name>\<group name>.

For example: CORP\SecurID Users

Group name:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
Value NameChallengeGroup
Value TypeREG_SZ
Default Value
Send Domain and User Name to Authentication Manager
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\RSA\RSA Desktop\Local Authentication Settings
Value NameSendDomainName
Value TypeREG_DWORD
Default Value0
True Value1
False Value0

rsa_authentication_agent.admx