How to setup On-Demand Authentication (ODA) in RSA Authentication Manager 8.x
Originally Published: 2014-05-07
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Cause
Resolution
Before completing the steps below, ensure you have successfully configured on-demand tokencode delivery. For more information see the online help topic entitled Configure On-Demand Tokencode Delivery.
You must have an Enterprise License for On-Demand Authentication or Risk Based Authentication (RBA). Confirm this in the Security Console under Setup > License Status.
Enable ODA for the user
- Search for the user in the Security Console under Identity > Users > Manage Existing.
- When the user in question is returned, click on the context arrow next to the user name and select SecurID Tokens.
- Hardware and software tokens assigned to the user are listed at the top of the page. Scroll down to the section labeled On-Demand Authentication (ODA).
- Check the option to enable the user for on-demand authentication.
- Optionally, you can set an expiration for this on-demand token.
- For Send On-Demand Tokencodes, ensure the correct attribute is set and update if needed.
- For the attribute, enter the email address or mobile number.
- For Associated PIN, choose to require the users to set the PIN through the Self-Service Console or set the initial PIN for the user.
- When done, click Save.
Using the On-Demand Token
- The user opens a browser window, VPN client or Windows login page and accesses the company web portal or protected resource (also known as an authentication agent).
- When prompted, the user enters their user ID and PIN
- A one time tokencode is sent to the users mobile phone via SMS or email.
- The user enters the tokencode into the browser/login page.
- The user gains access to the protected resource
You do not need to enable ODA or ODT on an agent. Check the RSA Ready implementation Guides for support on partner platforms with either SecurID or RADIUS protocol.
Notes
ODA Tokencode lifetime: The lifetime of an on-demand tokencode in RSA Authentication Manager is set by your administrator and it expires after one use or within the lifetime specified.
Related Articles
"No configured interfaces were detected" error after finishing Quick Setup on a new RSA Authentication Manager 8.4 server 515Number of Views How to reset table views to their original factory-set (OOTB) defaults in RSA Identity Governance & Lifecycle 33Number of Views Authentication Manager 8.x Quick Setup Access Code Not Displayed After Appliance Deployment 554Number of Views How to set cookie expiration times 25Number of Views RSA Authentication Manager 8.1 Quick Setup Fails with "Failed to Attach Replica Instance" 1.86KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Patches and Hotfixes Readme Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?