Three incorrect token passcodes on RSA Authentication Agent 7.4.x for WIndows causes the user's Active Directory account to lock
Originally Published: 2019-02-14
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4.x,, 7.3.3
Platform (Other): Windows
Issue
If we enter three incorrect passcodes the AD User account will become locked in AD. This behavior is only seen on a Windows agent, other agents do not lock AD accounts. This also occurs whether or not the Authentication Manager Identity source User Enable Status on the external Identity Source (AD) is configured as manage in both directory and AM or manage only in directory.
It was to our understanding that a lockout of SecurID was fully independent from the AD (Domain) account and that one cannot effect the other.
Cause
Enabling this policy would make the RSA agent respect Local or AD lockout policy settings, which in this case were set to three failures to produce a lockout.
Resolution
The Do Not Preserve History (default) mode enables display of descriptive authentication failure messages to users during log on but does not preserve failed authentication history for display at successful log on, when Windows is configured to show last interactive log on information.
Workaround
Related Articles
RSA Announces the Availability of RSA Authentication Manager 8.3 10Number of Views RSA Announces the May 2021 Release of RSA SecurID Access 13Number of Views RSA Announces RSA Authentication Manager 8.4 Now Available from the Azure Marketplace 11Number of Views Service Provider hangs at throughput of 5 assertions per second 16Number of Views Radiant Logic RadiantOne FID 7.3.12 - Identity Source with CAS Configuration - SecurID Access Implementation Guide 13Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes for RSA Authentication Manager 8.8 Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor…
Don't see what you're looking for?