Three incorrect token passcodes on RSA Authentication Agent 7.4.x for WIndows causes the user's Active Directory account to lock
Originally Published: 2019-02-14
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4.x,, 7.3.3
Platform (Other): Windows
Issue
If we enter three incorrect passcodes the AD User account will become locked in AD. This behavior is only seen on a Windows agent, other agents do not lock AD accounts. This also occurs whether or not the Authentication Manager Identity source User Enable Status on the external Identity Source (AD) is configured as manage in both directory and AM or manage only in directory.
It was to our understanding that a lockout of SecurID was fully independent from the AD (Domain) account and that one cannot effect the other.
Cause
Enabling this policy would make the RSA agent respect Local or AD lockout policy settings, which in this case were set to three failures to produce a lockout.
Resolution
The Do Not Preserve History (default) mode enables display of descriptive authentication failure messages to users during log on but does not preserve failed authentication history for display at successful log on, when Windows is configured to show last interactive log on information.
Workaround
Related Articles
RSA Announces the May 2021 Release of RSA SecurID Access 13Number of Views RSA Announces RSA Authentication Manager 8.4 Now Available from the Azure Marketplace 11Number of Views RSA Announces the Availability of RSA Authentication Manager 8.3 10Number of Views Upgrade from Microsoft Windows 10 to Windows 11 fails with certain versions of the RSA MFA Agent for Windows installed 17Number of Views Radiant Logic RadiantOne FID 7.3.12 - Identity Source with CAS Configuration - SecurID Access Implementation Guide 13Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide User Event Monitor Messages for Cloud Access Service (1501 - 20406) How to test RSA Identity Router (IDR) Secure Connector connectivity to the RSA ID Plus Cloud Access Service RSA Release Notes for RSA Authentication Manager 8.8 Troubleshooting RSA MFA Agent for Microsoft Windows
Don't see what you're looking for?