Configure Handling of Incorrect Passcodes
Occasionally, a user mistakenly enters a series of incorrect passcodes before entering the correct passcode. You can configure how AM handles these situations.
You can allow users to enter an unlimited number of incorrect passcodes, or limit the number of incorrect passcodes a user is allowed to enter. If you set a limit, when the limit is exceeded and followed by a correct passcode, users are prompted to enter the next tokencode that displays on their token.
This guards against situations in which an unauthorized person attempts to guess a passcode. In such a case, even if the person guessed a correct passcode, he or she is prompted for the next tokencode and given only one chance to enter it correctly. If the person enters the next tokencode incorrectly, the user account to which the token belongs is locked.
This behavior is controlled by the OTP authenticator policy assigned to individual security domains. To change this setting you must edit the policy.
Procedure
In the Security Console, click Authentication > Policies > Token Policies > Manage Existing.
Use the search fields to find the policy that you want to edit.
From the search results, click the policy that you want to edit.
From the context menu, click Edit.
Under Basics, for Incorrect Passcodes, specify how you want the deployment to respond when a user enters incorrect passcodes.
Click Save.
Related Concepts
Related Articles
Edit Cloud Authentication Service Connection 92Number of Views Cloud Access Service POC Quick Setup Guide - Step 4: Add an Access Policy 28Number of Views Add an Administrative Role 18Number of Views Deploy an Identity Router Virtual Machine in Microsoft Azure 98Number of Views RSA Announces the Availability of RSA Identity Management and Governance 6.9.1 Patch 25 1Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM