RSA ID Plus
RSA MFA Agent for Windows (all versions)
The RSA MFA Agent for Windows (MFA Agent) is logging a Warning event to Windows Event Viewer in category Applications and Services Logs > RSA MFA Agent.
The warning is logged with Event ID 1110 and the description System cannot access location data for this computer for user 'username'.
This warning only impacts authentications when:
- The MFA Agent is configured to connect to the RSA Cloud Authentication Service (CAS) either directly, or using RSA Authentication Manager as a secure proxy for CAS.
- The CAS Access Policy set in GPO Policy for the MFA Agent, has conditions that rely on collection of the IP address or location (latitude and longitude) of the computer where the MFA Agent is running. See page Condition Attributes for Access Policies . If the required location data cannot be collected, then it will default to an "untrusted" location or unknown IP address.
See also sections "Specify the Cloud Authentication Service Access Policy", "Collect System Attributes for Cloud Authentication Service Access Policy" and "Specify Location Collection Timeout" in the RSA MFA Agent for Microsoft Windows Group Policy Object Template Guide for your MFA Agent version.
The MFA Agent GPO Policy "Collect System Attributes for Cloud Authentication Service Access Policy" is either Not Configured (which defaults to Enabled), or it is Enabled. However, Microsoft Windows is unable to provide the MFA Agent with the location of the computer where it is running.
This can be because:
- Microsoft Windows' location service is disabled, or
- Microsoft Windows' location service is disabled for the RSA MFA Agent for Windows
- Microsoft Windows could not provide location information information within the timeout specified by the MFA Agent GPO Setting "Specify Location Collection Timeout", or
- Microsoft Windows encountered an error obtaining location or IP data, or
- Location information is temporarily unavailable (e.g. the computer's network connection is down)
- Check the RSA MFA Agent Cloud Authentication Service Access Policy in GPO to find out which CAS Access Policy is configured for the MFA Agent.
- Review that CAS Access Policy in the Cloud Administration Console to determine if it contains conditions that rely on IP address or location.
Next steps, depending on the Access Policy conditions are:
- If the CAS Access Policy does not have conditions that rely on collection of the IP address or location, then there is no need for the MFA Agent to collect location data. The warning can be ignored. However, to prevent unnecessary location checks and stop the warning being logged, it is preferable to change the MFA Agent GPO Policy "Collect System Attributes for Cloud Authentication Service Access Policy" to Disabled.
- If the CAS Access Policy does have conditions that rely on collection of the IP address or location:
- If the Microsoft Windows' location service is disabled, or disabled for the RSA MFA Agent for Windows, Enable it.
- If the Microsoft Windows' location service is enabled, the MFA Agent logs should be checked for any additional information that may help you troubleshoot the issue. To get the MFA Agent logs, follow the "Advanced Troubleshooting" steps in KB article Troubleshooting RSA MFA Agent for Microsoft Windows . At step 8b) get the following items:
- RSA MFA Agent Logs
- Windows Event Viewer (in each category, include all events around the date/time the issue has occurred)
- Windows Logs > Application
- Windows Logs > Security
- Windows Logs > System
- Applications and Services Logs > RSA MFA Agent
- For instructions to check or edit RSA MFA Agent GPO policies, see section "Accessing the Group Policy Object Template" in the RSA MFA Agent for Microsoft Windows Group Policy Object Template Guide for your MFA Agent version.
- Enabling/disabling Microsoft Windows Location Service:
- For Windows 10 and 11, see page https://support.microsoft.com/en-us/windows/windows-location-service-and-privacy-3a8eee0a-5b0b-dc07-eede-2a5ca1c49088 .
- For Microsoft Windows Server versions, check Microsoft documentation for your Windows server version, or contact Microsoft Support.
Related Articles
RSA Identity Governance and Lifecycle Role Sets display the Raw Name instead of the Name in multiple locations in the UI 39Number of Views Unknown cause error and size limit exceeded error when synchronizing LDAPv3 identity source with RSA SecurID Access Cloud … 58Number of Views After running a new automated campaign new users that are assigned to the questionnaire via inherited record permissions … 46Number of Views Z: Need to Finish: How to provision dynamic group memberships to a CA (Computer Associates) Directory using AFX in RSA Ide… 9Number of Views Update freezes when updating from RSA Authentication Manager 8.3 to Authentication Manager 8.3 patch 6 23Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide Downloading RSA Authentication Manager license files or RSA Software token seed records Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026)