CyberArk Authentication fails when using hardware tokens
9 months ago
Article Number
000073446
Applies To

RSA Product Set: SecurID

RSA Product Version: AM 8.x

 

Issue

Authentication using hardware tokens in CyberArk fails, and the Authentication Activity Monitor logs the error: "Bad tokencode but good PIN." This occurs even when the passcode is valid.

However, testing authentication with the same token and credentials is successful through the Self-Service Console. 

 

Cause

The failure occurs because the hardware token generates a passcode that combines a 4-digit PIN with a 6-digit tokencode, resulting in a 10-digit passcode. CyberArk does not accept passcodes of this length, leading to the "Bad tokencode but good PIN" error during authentication.

Resolution

As a workaround, disable the PIN requirement for the affected hardware tokens as outlined in this article Allow a User to Authenticate Without an RSA SecurID PIN.

Alternatively, contact CyberArk Support for further assistance.