Authentication Dashboard
a month ago

Authentication Dashboard

The Authentication Dashboard provides a comprehensive view of authentication activities, facilitating the monitoring and analysis of authentication patterns, including the number of successful and failed authentication counts, to ensure efficient access control within Cloud Access Service (CAS).

Access the Authentication Dashboard

Use the Authentication Dashboard to view authentication information for all users in your organization or for individual users within a specified timeframe.

Procedure 

  1. Sign in to the Cloud Administration Console.

  2. In the Cloud Administration Console, click Dashboards > Authentication.

The dashboard includes the following sections:

Total Number of Authentications

This section provides a comprehensive count of all authentication events within CAS over specified time periods. You can monitor the daily count of successful and failed authentication attempts.

Authentications per Day

This section provides a comprehensive overview of authentication activity for the past 7, 14, and 21 days, as well as the past month. It displays the daily count of both successful and failed authentication attempts, enabling you to track usage trends and detect any significant changes over the specified period.

By default, the bar chart displays authentication activity collected over the past 7 days for all users in your organization who have authenticated through CAS. To access more detailed information, select a specific day to view the breakdown of authentication activity per hour in the subsequent graph.

To retrieve and track user event logs from CAS, refer to the Cloud Administration User Event Log API

Successful and Failed Authentications

The following table lists the events tracked for successful authentications.

 

Event Code Description
103Authenticate OTP authentication succeeded.
107Identity router API SecurID OTP response received - Authentication succeeded.
201LDAP password authentication succeeded.
230Unified Directory user password authentication succeeded.
234Unified Directory user password authentication succeeded - password must be changed.
340FIDO authentication succeeded.
601Authentication Manager successfully authenticated SecurID OTP Credential.
660Cloud Authentication Service successfully validated Hardware Authenticator credentials.
701Approve authentication succeeded.
801Biometric authentication succeeded.
1501QR Code authentication succeeded.
500Cloud Identity Provider (IDP) authentication succeeded.
901Portal logon succeeded.
2651Successful OATH HOTP authentication.
20909OIDC - Successful user authentication through SSO.
20910OIDC - Successful user authentication through Relying Party.
20912OIDC - Successful user authentication through AAD Relying Party.
21901SMS OTP verification succeeded.
21951Voice OTP verification succeeded.
26000Emergency Access Code verification succeeded.
31101Verify OTP successful.

 

The following table lists the events tracked for failed authentications.

 

Event Code Description
30Authentication failed - Required parameter missing.
31Authentication failed - User does not exist.
32Authentication failed - User account disabled.
33Authentication failed - Application not found.
34Authentication failed - Rule not found.
35Authentication failed - Method locked.
36Authentication failed - Authenticator not registered or authentication method not enrolled.
37Authentication failed - Internal error.
38Authentication failed - Illegal access.
39Authentication failed - Identity Source disabled.
104Authenticate OTP authentication failed - Invalid OTP.
105Authenticate OTP authentication failed - Previously used OTP detected.
150Authenticate OTP authentication failed - Error occurred.
154Authenticate OTP authentication method locked - User exceeded maximum OTPs allowed.
108Identity router API SecurID OTP response received - Authentication failed.
109Identity router API SecurID OTP authentication failed - User not found in identity source.
110Identity router API SecurID OTP authentication failed - Username is associated with multiple user accounts.
111Identity router API SecurID OTP authentication failed - User account disabled in identity source.
112Identity router API SecurID OTP authentication failed - User email address not found in identity source.
113Identity router API SecurID OTP authentication failed - Identity source unreachable.
114Identity router API SecurID OTP authentication failed - Cloud Authentication Service unreachable.
202LDAP password authentication failed - Unknown cause.
203LDAP password authentication failed - Request timed out or identity router is not connected.
207Password authentication failed - User not found.
208Password authentication failed - Missing email or password.
209LDAP password authentication failed - Invalid DN.
211LDAP password authentication failed - LDAP server host unreachable. Invalid port or server is not running.
212LDAP password authentication failed - LDAP server host unresolvable.
213LDAP password authentication failed - Cannot establish a trusted SSL/TLS connection with the LDAP directory server. Check for invalid certificate.
215LDAP password authentication failed - Logon failure: unknown username or invalid password.
216LDAP password authentication failed - LDAP account restriction, for example logon time or policy restriction is enforced.
217LDAP password authentication failed - Time restriction prevents logon for this LDAP account.
218LDAP password authentication failed - LDAP account not permitted to authenticate via this identity router.
219LDAP password authentication failed - LDAP password expired.
220LDAP password authentication failed - LDAP account disabled.
221LDAP password authentication failed - LDAP account configuration prevents logon.
222LDAP password authentication failed - LDAP account expired.
223LDAP password authentication failed - LDAP password must be changed using your company's internal procedures.
224LDAP password authentication failed - LDAP account locked out.
225LDAP password authentication failed - LDAP password locked for specified lockout duration.
231Unified Directory user password authentication failed - Unknown cause.
232Unified Directory user password authentication failed - Unknown username or invalid password.
233Unified Directory user password authentication failed - Password locked for specified lockout duration.
236Unified Directory user password authentication failed - password must be changed.
238Unified Directory user password authentication failed - Password authentication is not allowed for users in the identity source.
341FIDO authentication failed - FIDO protocol error.
342FIDO authentication failed - RSA SecurID Access service error.
343FIDO authentication failed - Unknown error.
344FIDO authentication failed - FIDO token disabled.
405Just-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Disabled in directory server.
407Just-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Unknown reason.
411Just-in-time synchronization failed to synchronize user with the Cloud Authentication Service - User not found.
605Authentication Manager unable to authenticate SecurID OTP Credential - Invalid OTP.
606Authentication Manager unable to authenticate SecurID OTP Credential - Invalid next OTP.
607Authentication Manager unable to authenticate SecurID OTP Credential - Invalid PIN.
608Unable to authenticate SecurID OTP Credential – Authentication Manager service unavailable.
609Authentication Manager unable to authenticate SecurID OTP Credential - Unknown cause.
611Authentication Manager unable to authenticate SecurID OTP Credential - Request timed out.
663Hardware Authenticator authentication to Cloud Authentication Service failed - Invalid PIN and/or OTP.
664Hardware Authenticator authentication to Cloud Authentication Service failed - Previously used OTP was reused for authentication.
665Hardware Authenticator authentication to Cloud Authentication Service failed - Authenticator PIN not set.
666Hardware Authenticator authentication to Cloud Authentication Service failed - Authenticator expired.
667Hardware Authenticator authentication to Cloud Authentication Service failed - Authenticator disabled.
671Hardware Authenticator authentication to Cloud Authentication Service failed - Authenticator credentials cannot be verified.
702Approve authentication failed - User response timed out.
703Approve authentication failed - User denied approval.
705Approve authentication failed - Invalid credentials submitted.
706Approve authentication failed - Operation is not allowed.
708Approve authentication failed - No token found.
709Approve authentication failed - All in-progress authentication requests cancelled.
710Approve authentication cancelled.
802Biometric authentication failed - User response timed out.
803Biometric authentication failed - User denied access to biometric credentials.
805Biometric authentication failed - Unexpected error.
808Biometric authentication failed - All in-progress authentication requests cancelled.
809Biometric authentication failed - Authenticator not found.
810Biometric authentication cancelled.
1503QR Code authentication failed - User denied approval.
1505QR Code authentication failed - Invalid QR code.
1506QR Code authentication failed - Operation is not allowed.
1508QR Code authentication failed - Empty QR code found.
1510QR Code authentication cancelled.
1513QR Code authentication failed - QR code has expired.
501Cloud Identity Provider (IDP) authentication failed.
902Portal logon failed - Authentication failed.
903Portal logon failed - Credentials are associated with multiple user accounts.
904Portal logon failed - Internal server error.
905Portal logon failed - Concurrent session limit reached.
906Portal logon failed - Password reset required.
933Password authentication succeeded - Client does not support required additional authentication methods - Access denied.
935Unsuccessful password authentication - Access denied.
940Password authentication succeeded - User prohibited by policy settings - Access denied.
941Password authentication succeeded - Access prohibited by conditional policy settings - Access denied.
2650Unified OTP authentication factor does not match policy.
2652OATH HOTP authentication failed due to invalid OTP.
2653OATH HOTP authentication failed due to the factor being locked.
2654OATH HOTP authentication to Cloud Authentication Service failed as the authenticator credentials cannot be verified.
2655OATH HOTP authentication to Cloud Authentication Service failed as the authenticator is disabled.
2656OATH HOTP authentication failed as the authenticator has no PIN set.
2657OATH HOTP authentication failed due to invalid PIN and/or OTP.
20601RADIUS - LDAP authentication succeeded - Access denied. Policy does not contain RADIUS-compatible methods for additional authentication.
20602RADIUS - LDAP authentication succeeded - Access denied. No authenticators were found for additional authentication methods.
20603RADIUS - Invalid format for additional authentication request - Access denied.
20604RADIUS - Invalid checklist attributes - Access denied.
20605RADIUS - Cloud Authentication Service request timed out - Access denied.
20606RADIUS - Approve authentication failed - Method timeout.
20608RADIUS - Biometric authentication failed - Method timeout.
20609RADIUS - Authentication failed - Internal error.
20610RADIUS - Approve authentication failed - Authentication could not be completed within push notification timeout.
20611RADIUS - Biometric authentication failed - Authentication could not be completed within push notification timeout.
20615RADIUS - Authentication failed.
20701Access denied - User not a member of any identity source in access policy.
20702Access denied - User does not match rule set in access policy.
20703Access denied - Policy authentication conditions deny access.
20802SMS OTP message transmission attempt failed - Invalid phone number.
20803SMS OTP message transmission attempt failed.
20805SMS OTP delivery failed.
20852Voice OTP call attempt failed - Invalid phone number.
20853Voice OTP call attempt failed.
20855Voice OTP delivery failed.
20902OIDC - Response sent for unsuccessful user authentication.
20903OIDC - Error response sent.
20905OIDC - User has denied access to resource.
21902SMS OTP verification failed.
21904SMS OTP verification failed – internal error.
21952Voice OTP verification failed.
21954Voice OTP verification failed – internal error.
26001Emergency Access Code verification failed.
26002Emergency Access Code not configured.
26003Emergency Access Code is expired.
26004Emergency Access Code locked - User previously exceeded maximum attempts.
26005Emergency Access Code now locked.
31102Verify OTP failed - OTP don't match.
31103Verify OTP Expired - Verify OTP Expired.
31104Verify OTP failed - Verify OTP retry exhausted.
31105Verify OTP failed - Verify OTP not generated or not found.
31106Verify OTP failed - Verify OTP mode is incorrect.

 

Authentications per Hour

This section allows you to explore detailed authentication activity breakdowns by hour. You can select specific data points to visualize the hourly distribution of authentication events. This detailed view helps identify peak activity periods and understand patterns of success or failure rates within daily operations.

Authentications per User

This table summarizes authentication activities for each user, displaying their user ID along with counts of successful and failed authentication attempts. You can select a user's row to view detailed data on the applications accessed and the authenticators used by that user. When a user is selected in the "Authentications per User" section, all authentication events linked to that user are simultaneously displayed in the "Authentications per App" and "Authentications per Authenticator" sections. This integration enables you to gain a comprehensive understanding of the applications accessed and the authenticators utilized by the selected user.

The value UNKNOWN in the graph signifies that the authentication event did not include details about the user attempting to authenticate. This can occur when the authentication process fails before the user was evaluated.

Authentications per Application

This section visualizes how authentication events are distributed across applications or resources associated with the selected user. This graph highlights which applications the user has accessed and displays the number of successful and failed authentication attempts for each application over a specified period.

The value OTHER in the graph signifies that the application and authenticator were unavailable for that event. This can occur in several scenarios, such as:

  • The user was not authenticating to an application, but rather an MFA API call was made to evaluate credentials or a policy.

  • The authentication failed before the product could begin evaluating the target application.

Authentications per Authenticator

This section displays the distribution of authentication events across different authenticators used by the selected user. The graph provides insights into the specific authenticators used by the user and shows the counts of successful and failed authentication attempts associated with each authenticator over a specified period.

The value OTHER in the graph signifies that the application and authenticator were unavailable for that event. This can occur in several scenarios, such as:

  • The user was not authenticating to an application, but rather an MFA API call was made to evaluate credentials or a policy.

  • The authentication failed before the product could begin evaluating the target application.

  • The authentication failed before the product could start assessing the user's credentials.