RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
- In Authentication Manager 8.x and later, the following error is displayed for all software tokens, but hardware tokens and fixed passcodes work:
- The passcode format error occurs with native SecurID agents, as well as RADIUS clients and their associated agents.
- RSA SecuriD software tokens on user devices will fail to resynchronize in the Security Console.
In the screen shot below note that the following warning is issued:
If you click OK, another warning displays:You will issue <number of software tokens> software tokens according to your selection criteria. This job generates new token seeds for these tokens. Existing users of these tokens will no longer be able to authenticate. Users must import the new token data before they can authenticate.
Once the new token seed is issued, the Authentication Manager server will expect authentication requests to use the newly issued tokencode or passcode. Since the old token is still installed on the end user's mobile device or desktop, when a tokencode or passcode is submitted from the device, authentication will fail.
Currently there is no simple or easy way to prevent this from happening. There is currently an RFE in place (AM-30216) to change the bulk distribution of software tokens within Authentication Manager.
There is no rollback option in Authentication Manager if software tokens are redistributed
. The two options to resolve this issue if it happens in your deployment are as follows:- Either provide the new token seeds to the end users so they can import the new token to their device.
- Alternatively, revert to a backup of your Authentication Manager system, or restore from Backup in the Operations Console. Restoring from a backup means losing some data that has changed since the backup was taken. Make absolutely sure you restore the correct backup, as the Operations Console will take whatever backup you point to and overwrite current system. May want to backup now of current system before restoring from backup as a safety measure.
Recommendations
- Before choosing the option to distribute software tokens in bulk, login to the Operations Console and select Maintenance > Backup and Restore > Backup Now to take a backup of the Authentication Manager database.
- As part of best practices for Authentication Manager, configure scheduled backups in the Operations Console (Maintenance > Backup and Restore > Schedule Backups) to backup the database on a regular schedule so that if this issue happens, it can be mitigated quickly.
Related Articles
Reporting on SecurID software tokens with software token lifetime extension in RSA Authentication Manager 8.x 950Number of Views Are RSA SecurID hardware and software tokens FIPS 140-2 compliant? 639Number of Views Assign Software Tokens to Multiple Users 60Number of Views RSA RSA SecurID - Force all tokens to be in New PIN mode without clearing PIN 308Number of Views Maximum Tokens Exceeded message while importing RSA SecurID software tokens to the RSA SecurID Software Token for Microsof… 134Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM