This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Knowledge Base

Find answers to your questions and identify resolutions for known issues with knowledge base articles written by SecurID experts.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Knowledge Base
  • :
  • Authentication error occurs when additional authentication is required for RSA SecurID Access applic...
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Authentication error occurs when additional authentication is required for RSA SecurID Access application portal or a protected application

Article Number

000036224

Applies To

RSA Product Set:  SecurID Access

Issue

When attempting to access the IDR-hosted application portal with additional authentication required (or an application in the portal that requires additional authentication) the following error occurs:
 
Authentication error
Image descriptionImage description

The /var/log/symplified/symplified.log includes a message like:
 
2018-04-05/18:50:20.627/UTC [ajp-bio-8009-exec-7] WARN com.symplified.service.appliance.cloudmfa.CloudMFAUtils[37] - Failed strong authentication: AUTHN_ATTEMPT_ID_NOT_FOUND
 
The User Event Monitor shows an authentication failure with Authentication Details AUTHN_ATTEMPT_ID_NOT_FOUND.

Cause

Possible causes are:
  • The user is in an associated LDAP identity source but has not been synchronized to the Cloud yet.
  • The user has been synchronized to the Cloud but a step-up authentication is required and the user is not registered for any of the allowed step-up authentication options.
  • Two users in different identity sources are synchronized to the Cloud with the same user ID.  A step-up authentication is required and at least one of the two users is not registered for any of the allowed step-up authentication options.

Resolution

First, use the Cloud Administration Console's User > Management page or run User Reports to check for user status, devices registered to a user, and to check for duplicate user id's.  This will allow you to determine which possible cause applies.

Next, take the appropriate step below, depending on the cause of the issue, to ensure the user is correctly sync'd to the Cloud.
  • The user is in an associated LDAP identity source but has not been synced to the Cloud yet.
Follow the steps in Manually Synchronize an Identity Source for the Cloud Authentication Service to create a record of the user in the SecurID Access cloud service.
  • The user has been synced to the Cloud but a step-up authentication is required and the user is not registered for any of the allowed step-up authentication options.
Ensure that the user has a device registered to perform the required additional authentication.  For example, see RSA SecurID Authenticate Device Registration Overview if approve (push notification) or authenticate tokencodes are allowable authentication methods.
  • Two users in different identity sources are sync'd to the Cloud with the same user id.  A step-up authentication is required and at least one of the two users is not registered for any of the allowed step-up authentication options.
Delete the unwanted user from the Cloud Authentication Service, and from the identity source.

Lastly, ensure that the user has the ability to perform the required additional authentication.  For example, see RSA SecurID Authenticate Device Registration Overview if approve (push notification) or authenticate tokencodes are allowable authentication methods, or ensure the user's correct telephone is registered for SMS or Voice Token Code authentication.
Tags (38)
  • All Versions
  • Any Version
  • Auth
  • Auth Issue
  • Authentication
  • Authentication Issue
  • Break Fix
  • Break Fix Issue
  • Broken
  • Can't Log In
  • Can't Login
  • Cannot Log In
  • CAS
  • Cloud Auth Service
  • Cloud Authentication Service
  • Customer Support Article
  • Every Version
  • Failed Login
  • Issue
  • Issues
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Login
  • Login Issue
  • Problem
  • RSA SecurID
  • RSA SecurID Access
  • RSA SecurID Suite
  • SaaS
  • SecurID
  • SecurID Access
  • SecurID Access Cloud
  • SecurID Cloud
  • SecurID Suite
  • Software as a Service
  • Unable to log In
  • Version Agnostic
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2020-12-12 07:27 PM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.