Desktop, X11 & Wayland

A privileged desktop action has no authentication agent

A working polkit daemon does not guarantee a password dialog in a custom desktop. Inspect the session and its registered authentication agent.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • A disk or network settings action shows no authentication dialog.
  • pkexec reports that no authentication agent was found.

Relevant environment

Desktop actions using polkit; minimal window-manager sessions may need a separate agent. This is distinct from sudo prompting.

Recognizable messages (synthetic examples)
Error executing command as another user: No authentication agent found.

Check the desktop session and agent; do not interpret this as a wrong password or authorization to bypass policy.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • No desktop authentication agent may be running or registered for this session.
  • The process may be associated with another or inactive login session.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Reads the invoking process’s login session where logind is used; run from the same desktop launch context.

loginctl session-status

Interpret the result: Check the intended account and active/local session. An SSH session is not interchangeable with the GUI session for policy decisions.

Check 2

Reads this boot’s authority-service messages; journal permissions and the unit name vary by distribution.

journalctl -b -u polkit.service --no-pager

Interpret the result: Correlate agent registration/unregistration with the desktop’s session ID. A running polkit service alone does not show a usable prompt agent.

Evidence-guided next steps

Start the intended desktop’s authentication agent

If the desktop provides an agent but its autostart entry is disabled, restore that entry for the affected session. For a minimal WM, install the distribution’s supported agent and start exactly one instance through the WM’s documented session startup as the logged-in user.

Precautions: Do not launch the agent as root or grant all polkit actions globally to avoid the dialog. Agent executable paths differ by distribution.

Recovery / rollback: Disable only the autostart entry added for this fix and end its agent process, or restore the saved desktop autostart setting.

Did this solution help you?

Share this solution#

Run the action in its intended active session

If registration exists for another session, close the stale launcher and start the action from the intended desktop account’s active session. If login integration is broken, repair the distribution’s supported PAM/session configuration with a saved backup and console access before relogin.

Precautions: A registered agent cannot authorize an operation excluded by policy. A cancelled or denied request differs from an absent agent.

Recovery / rollback: Restore the saved login configuration from the working console and start a fresh session; undo only the launcher changes made here.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.