RSA Authentication Manager 8.1 SP1 On Demand Authentication requires that the initial PIN be set in the Self-Service Console fails because there is no PIN yet
Originally Published: 2016-08-02
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 SP1 and later
Issue
- Once the user is enabled for ODA, he cannot use the Self Service Console (SSC) to set his PIN because the SSC is prompting for a PIN after the user enters his password.
- As shown here, the Self-Service Console (SSC) logon screen requests Jay's user ID and password.
- The SSC then prompts Jay to enter an existing PIN rather than asking him to create a new PIN.
- Logon fails because a PIN is not set yet. Using a blank PIN or a PIN of 0000 also fails.
- In the Security Console, the enable ODA options show a choice between:
- Require user to setup the PIN through RSA Self-Service Console
- System generate initial PINs for selected users and export them to a file
- The option of system generated initial PIN only worked in Authentication Manager 7.1. All the Authentication Manager 8.1 systems here show that the option is:
Set initial PIN to [ ] (Pin needs to be communicated to user)
- This works if we use the System Generate PINs option. We download the file, logon to the SSC with a password, enter the PIN, then create a new PIN.
- If we select Require user to setup the PIN, and the user logs on to the Security Console, he is prompted to enter a PIN, even though Security Console says PIN not set. Nothing works and the user sees a message of either logon failed or if the PIN is blank, that the field is required
Cause
Resolution
- Manually set ODA user PINs in the Security Console or with the Authentication Manager Bulk Administration (AMBA) tool; or
- Change the Self-Service logon requirements to not enforce an ODA logon, either by removing it completely or by making it optional with the OR operator (that is, /).
Workaround
- Generate PINs for the users.
- Communicate the PINs in a secure manner to the end users.
Related Articles
Initial Troubleshooting Steps for CProfileUpdater Not Working in RSA Web Threat Detection 18Number of Views Set an Initial On-Demand Authentication PIN for a User 41Number of Views RSA Authentication Manager 8.2 SP1 upgrade fails with the error: "Configuration step RadiusOCConfig.configureActualRADIUSS… 391Number of Views AFX Server on Windows fails to stop/start after initial successful start in RSA Governance & Lifecycle 153Number of Views How to reset table views to their original factory-set (OOTB) defaults in RSA Identity Governance & Lifecycle 33Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1
Don't see what you're looking for?