RSA Product Set: SecurID Access
RSA Product/Service Type: Authentication Agent for Active Directory Federation Services (AD FS)
RSA Version/Condition: 3.X
The RSA MFA Agent 3.x is installed and configured on AD FS for Windows. However, when accessing the AD FS test page and clicking "Sign In," users are able to log in using only their password. The agent is not prompting for multi-factor authentication as expected, indicating that the MFA challenge is not being triggered during the authentication flow.
In the AD FS test configuration, the Relying Party Identifier was incorrectly set to use https instead of http. As per the official RSA MFA Agent 3.0 for Microsoft AD FS Administrator's Guide, the test configuration for the identifier should explicitly use http (e.g., http://<youradfs>.<yourdomain>.com/adfs/services/trust).
Once the identifier was corrected from https to http, the MFA prompt was successfully triggered on the test page.
To resolve the issue, update the Relying Party Identifier to use http by following these steps:
-
Open AD FS Management on the server.
-
Navigate to Application Groups in the left-hand pane.
-
Locate and double-click the application group used for the MFA test (e.g., Test MFA).
-
Under Applications, select the Web application and click Edit.
-
In the Identifiers tab, locate the Relying party identifier.
-
Remove the existing
https://<youradfs>...entry. -
Add a new identifier using
http, e.g.,http://<youradfs>.<yourdomain>.com/adfs/services/trust. -
Click Add, then OK, and then Apply to save the changes.
-
Close and reopen the test sign-in page and retry. MFA should now be triggered as expected.
Related Articles
RSA ACE/Agent 5.6 not prompting for Windows login during remote authentications 21Number of Views RSA MFA Agent for Windows delay getting the MFA prompt after credentials are entered 92Number of Views When switching to root the RSA Authentication Agent 8.1.3 for PAM is not prompting for a passcode 169Number of Views RSA Authentication Agent 8.6 API does not prompt for passcode with Epic Hyperspace 2016 on Windows Server 141Number of Views Allow the Use of Nonstandard Email Domains 17Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Release Notes for RSA Authentication Manager 8.8 Deploying RSA Authenticator 6.2.2 for Windows Using DISM