How users can generate a temporary emergency access tokencode from RSA Authentication Manager 8.x Self-Service Console
2 months ago
Originally Published: 2018-09-21
Article Number
000063495
Applies To
RSA Product Set:  SecurID
RSA Product/Service Type:  Authentication Manager
RSA Version/Condition:  8.x
 
Issue

This article explains how users can generate a temporary emergency access tokencode from the RSA Authentication Manager Self-Service Console without contacting their RSA help desk.
This is useful if the end-user has misplaced their token or forgotten to carry their assigned token to their workplace.

Tasks
The administrator with the super admin role needs to setup the following on the Authentication Manager primary server:

Configure Self-Service Settings

  1. From the Security Console, click Setup > Self-Service Settings.
  2. On the Settings page, select Customization
  3. Click Enable or Disable Self-Service Features.
  4. Enable the following options:
  • For Provisioning, enable provisioning features.
  • For Log On Section, enable Display Log on Section.
  • For Troubleshooting Links, enable Display Troubleshooting links.
  • For Set Display Options for Troubleshooting, enable Display Token is temporarily unavailable for misplaced option.
User-added image
  1. Click Save.
  2. In the Security Console, click Setup > Self-Service Settings.
  3. Select Manage Authenticators.
  4. In the Emergency Access Tokencode Settings section, select Allow user to place token in emergency access mode

 User-added image

  1. In the Emergency Access Tokencode Settings for Temporarily Unavailable Tokens section, use the Emergency Access Tokencode Lifetime fields to enter the length of time you want emergency access tokencodes to remain active. 
User-added image
  1. When done, click Save.
Resolution
Users can login to the Self-Service Console using their password and generate a temporary emergency access tokencode to authenticate.
  1. Login to the Self-Service Console.
  2. Click Troubleshoot
User-added image
  1. Select the option that the token is temporarily unavailable or misplaced.
  2. Click OK
User-added image
  1. An emergency access tokencode is generated for the user.
  2. The user can now use the emergency access tokencode to authenticate. Use the Test Log On button to confirm. 
User-added image
Notes
  • The emergency access tokencode can be used more than once if the emergency access tokencode settings are set to Temporary Fixed tokencode (TFT); however a set of On time tokencodes (OTT) is valid once.
  • If you have a SecurID PIN, log on with your PIN + the emergency access tokencode.
  • If you do not have a SecurID PIN: Use only the emergency access tokencode.