User Event Monitor Messages for Cloud Access Service (1501 - 20406)
a month ago

User Event Monitor Messages for Cloud Access Service (1501 - 20406)

User events trigger the following messages to appear in the User Event Monitor. New user events have been added and descriptions for some of the events have been modified recently. If these descriptions are used for SIEM integrations, they must be modified accordingly.

Event Code Level Category Description
1501noticeAuthenticationQR Code authentication succeeded.
1503errorAuthenticationQR Code authentication failed - User denied approval.
1504errorAuthenticationQR Code enrollment failed.
1505errorAuthenticationQR Code authentication failed - Invalid QR code.
1506errorAuthenticationQR Code authentication failed - Operation is not allowed.
1507noticeAuthenticationQR Code enrollment succeeded.
1508errorAuthenticationQR Code authentication failed - Empty QR code found.
1510errorAuthenticationQR Code authentication cancelled.
1511noticeAuthenticationQR Code unenrollment succeeded.
1512noticeAuthenticationQR Code unenrollment failed.
1513errorAuthenticationQR Code authentication failed - QR code has expired.
1515errorAuthenticationQR Code authentication failed - Disabled device platform.
1521noticeAuthenticationQR Code (RSA Agent) authentication succeeded.
1523 errorAuthenticationQR Code (RSA Agent) authentication failed - User denied approval.
1524noticeAuthenticationQR Code (RSA Agent) enrollment failed.
1525errorAuthenticationQR Code (RSA Agent) authentication failed - Invalid QR code.
1526 errorAuthenticationQR Code (RSA Agent) authentication failed - Operation is not allowed.
1527 noticeAuthenticationQR Code (RSA Agent) enrollment succeeded.
1528errorAuthenticationQR Code (RSA Agent) authentication failed - Empty QR code found.
1530 noticeAuthenticationQR Code (RSA Agent) authentication cancelled.
1531 noticeAuthenticationQR Code (RSA Agent) unenrollment succeeded.
1532 noticeAuthenticationQR Code (RSA Agent) unenrollment failed.
1533 errorAuthenticationQR Code (RSA Agent) authentication failed - QR code has expired.
1534noticeAuthenticationQR Code (RSA Agent) username is required but it is empty.
1536errorAuthenticationQR Code (RSA Agent) authentication failed - Disabled Device platform.
2605noticeAuthenticationOATH HOTP hardware authenticator enrolled successfully.
2607errorAuthenticationOATH HOTP Device Unknown Event.
2608errorAuthenticationOATH HOTP hardware authenticator enrollment failed.
2609errorAuthenticationCloud Authentication Service unable to synchronize OATH HOTP Hardware Authenticator due to an invalid OTP.
2610noticeAuthenticationOATH HOTP hardware authenticator resynced successfully.
2612errorAuthenticationOATH HOTP hardware authenticator resync failed as the authenticator is disabled.
2613errorAuthenticationOATH HOTP Hardware Device Resync failed - Authenticator not found.
2650errorAuthenticationUnified OTP authentication factor does not match policy.
2651 noticeAuthenticationSuccessful OATH HOTP authentication.
2652errorAuthenticationOATH HOTP authentication failed due to invalid OTP.
2653 errorAuthenticationOATH HOTP authentication failed due to the factor being locked.
2654errorAuthenticationOATH HOTP authentication to the Cloud Authentication Service failed as the authenticator credentials cannot be verified.
2655errorAuthenticationOATH HOTP authentication to Cloud Authentication Service failed as the authenticator is disabled.
2656errorAuthenticationOATH HOTP authentication failed as the authenticator has no PIN set.
2657errorAuthenticationOATH HOTP authentication failed due to invalid PIN and/or OTP.
2658noticeAuthenticationOATH HOTP device enter next code mode.
3000 notice My Authenticators Authenticator registration succeeded.
3001 error My Authenticators Authenticator registration failed.
3002 error My Authenticators Authenticator registration failed. Maximum number of authenticators exceeded for this user.
3003noticeAuthenticationAuthenticator authentication successful.
3004errorAuthenticationAuthenticator authentication unsuccessful.
3005noticeMy Authenticators

User deleted Authenticator in RSA SecurID Authenticator.

3006errorMy AuthenticatorsAuthenticator deletion failed.
3007noticeMy AuthenticatorsAuthenticator update succeeded.
3008errorMy AuthenticatorsAuthenticator update failed.
3009errorMy AuthenticatorsAuthenticator registration failed. Registration was denied by the policy.
3010noticeMy AuthenticatorsRSA SecurID Authenticate registration started with notifications disabled.
3012noticeMy AuthenticatorsRegistration code validation succeeded.
3013errorMy AuthenticatorsOffline service authentication verification failed.
3014noticeMy AuthenticatorsOffline day data download successful.
3015errorMy AuthenticatorsOffline day data download unsuccessful.
3016noticeAuthenticationOffline Emergency Access Code download successful.
3017errorAuthenticationOffline Emergency Access Code download unsuccessful.
3019noticeMy AuthenticatorsEmail sent to user for registration with the RSA SecurID Authenticator.
3020noticeMy AuthenticatorsEmail sent to user for RSA SecurID Authenticate authenticator deletion.
3021noticeMy AuthenticatorsOffline certificate enrollment successful.
3022errorMy AuthenticatorsOffline certificate enrollment unsuccessful.
4000notice VerificationSuccessful verification authentication.
4001errorVerificationVerification authentication failed.
4003noticeVerificationVerification authentication initiated.
5000noticeVerificationSuccessful identity verification.
5001errorVerificationIdentity Verification failed.
5002noticeVerificationIdentity Verification initiated.
5104errorAuthenticationCloud Administration Console logon failed - User account inactive.
5107 notice Authentication RSA SecurID Access admin password changed.
20300errorAuthenticationMultifactor authentication failed to initiate.
20301noticeAuthenticationMultifactor authentication initiated.
20302noticeAuthenticationMultifactor authentication succeeded.
20303errorAuthenticationMultifactor authentication was unsuccessful.
20304noticeAuthenticationMultifactor authentication complete - policy allowed access without additional authentication.
20306noticeAuthenticationSuccessful user authentication through Epic Hyperdrive Relying Party.
20308noticeAuthenticationMultifactor authentication from Authentication Manager is initiated.
20309noticeAuthenticationMultifactor authentication from Authentication Manager succeeded.
20310errorAuthenticationMultifactor authentication from Authentication Manager was unsuccessful.
20311errorAuthenticationMultifactor authentication failed as it timed out due to inactivity.
20400noticeAuthenticationSAML IdP - Authentication request received.
20401noticeAuthenticationSAML IdP - Assertion sent for successful user authentication.
20402errorAuthenticationSAML IdP - Response sent for unsuccessful user authentication.
20403errorAuthentication

SAML IdP - Error response sent.

If Authentication Details includes "Message was rejected due to issue instant expiration" or "Message was rejected because was issued in the future," then there might be a time-synchronization issue between the service provider and the Cloud Authentication Service. If you see this message during an additional authentication flow for an IDR SSO Agent application, check the time on the identity router.

20404noticeAuthenticationSAML IdP App - Assertion sent for successful user authentication.
20405noticeAuthenticationSAML SP App - Assertion sent for successful user authentication.
20406noticeAuthenticationSAML RP - Assertion sent for successful user authentication.

 

See:

User Event Monitor Messages for Cloud Access Service (02 - 345)

User Event Monitor Messages for Cloud Access Service (400 - 1409)

User Event Monitor Messages for Cloud Access Service (20601 - 38000)