RSA MFA Agent for Microsoft Windows failed to download offline days
2 months ago
Article Number
000068015
Applies To

RSA Product Set: SecurID Access
RSA Product/Service Type: RSA MFA Agent for Microsoft Windows
Version(s): 2.x

Issue

The article describes an issue that causes offline days to fail to download if the agent name is not the same on the security console and the windows GPO "and it is case sensitive".

Cause
  • An RSA MFA Agent for Windows is created on the Security Console under Access > Authentication Agents and is named mfa, all in lower case:


  • The same agent is named in the Group Policies as Mfa, where the first letter is capitalized:


  • If the above two scenarios are met when testing online authentication, the test connection will be successful but the offline days will fail to download.

    Offline authentication logs will show the following error:
    [Local: 2022-11-23 04:13:52.095] 2022-11-23 02:13:52.095 7136.1 [V] [RSA.Authentication.Mfa.OfflineAuthenticationAttempt.CheckOfflineFilesAvailableForUser] Enter
    [Local: 2022-11-23 04:13:52.111] 2022-11-23 02:13:52.111 7136.1 [V] [RSA.Authentication.Mfa.OfflineAuthenticationAttempt.CheckOfflineFilesAvailableForUser] Calling DayFileSvcClient.IsOfflineFilesAvailableForUser
    [Local: 2022-11-23 04:13:52.205] 2022-11-23 02:13:52.205 7136.1 [V] [RSA.Authentication.Mfa.OfflineAuthenticationAttempt.CheckOfflineFilesAvailableForUser] Return
    [Local: 2022-11-23 04:13:52.205] 2022-11-23 02:13:52.205 7136.1 [V] [RSA.Authentication.Mfa.OfflineAuthenticationAttempt.PerformAuthentication] Return
    [Local: 2022-11-23 04:13:52.205] 2022-11-23 02:13:52.205 7136.1 [I] [RSA.Authentication.Mfa.Authenticator.AttemptOfflineAuthentication] Returning: NoOfflineDataAvailable


     

Resolution

Make sure to enter the exact name of the agent specified in the Security Console when configuring the group policy.