Summary
In this new release, RSA SecurID Authenticator App 5.1provides a seamless migration of Authentication Manager OTPs from RSA SecurID Software Token app 4.2.3
to the latest version 5.1.
Details
RSA provides an easy way to migrate software tokens from the RSA SecurID Software Token app 4.2.3 to the new SecurID Authenticator 5.1 with the help of a migration tool called SecurIDMigrationHelper App. This tool ensures the keychain details are copied and credentials are moved to the new Authenticator app securely. Administrators need to ensure this migration helper tool is downloaded from the RSA Community link and copied to the macOS machines where both the old app (4.2.3) and the new Authenticator app (5.1) are installed. Once executed successfully, the copying of credentials takes place automatically without intervention from the end-user on the subsequent launch of the Authenticator app. The tool has to be re-executed manually only in rare scenarios where the device password has been reset or changed on the RSA SecurID Software Token app 4.2.3 after the initial migration.
EOPS for RSA SecurID Software Token app 4.2.3
RSA SecurID Software Token app 4.2.3 already reached the end of support by December 2022. Therefore, RSA recommends that you replace this app with the new SecurID Authenticator 5.1 app and migrate all the existing software tokens (AM OTP credentials) to the new Authenticator app.
For EOPS details, refer to SecurID Software Token product version life cycle.
Pre-requisite
To download and run the migration helper app, follow the below procedure:
- Go to RSA Community link.
- Click the SecurID Authenticator 1.0 macOS Migration Helper link to download and extract the RSA_Authenticator_Migration_Helper_1_0_for_macOS.zip file.
- Run the SecurIDMigrationHelper.app
application to migrate the RSA SecurID Software Token Credential keychain entries.
- Read the on-screen instructions, and then click Ok to proceed.
If a user removes or changes the device password of RSA SecurID Software token 4.2.3 after migration, the user should run the migration helper app again
Procedure
Migration Flow (Default)
After the successful execution of the migration helper app and if RSA SecurID Software Token 4.2.3 is already installed, users just need to launch the SecurID Authenticator 5.1 to automatically detect and migrate the SecurID OTP credentials from RSA SecurID Software Token 4.2.3.
Figure 1- Data Migration on Installation /Launch
Migration Flow (with Custom DB Location)
If the Custom Database location is configured in RSA SecurID Software Token 4.2.3, SecurID Authenticator 5.1 prompts the user to select the database file for migrating all OTP credentials automatically. When Custom Database location is configured on 4.2.3 and the user decides to migrate their credentials later, they will have to relaunch the application to initiate migration.
Figure 2- Manual data migration when Custom Database Location is set in RSA SecurID Software Token 4.2.3
Migration Flow (with Device Password)
SecurID Authenticator will prompt for a device password during migration if users have set a device password in RSA SecurID Software Token 4.2.3 and/or SecurID Authenticator 5.1.When device password is set and the user decides to migrate their credentials later they will have to relaunch the application to initiate migration.
Figure 3- Manual Data Migration when device password is configured(certain texts may slightly be adjusted in the released version)
These migration processes will not remove RSA SecurID Software Token 4.2.3 from the user’s Mac computer automatically. After the migration is successfully completed, users can safely remove RSA SecurID Software Token 4.2.3 manually.
Related Articles
'ORA-28000: the account is locked' error when migrating an imported database in RSA Identity Governance & Lifecycle 186Number of Views Migrating from RSA Authenticate App to SecurID Authenticator App 140Number of Views Radius clients are not listed after migrating from 7.1 to 8.1 158Number of Views Migrating users across identity sources in RSA Authentication Manager 8.x 1.93KNumber of Views ORA-01451: column to be modified to NULL cannot be modified to NULL error while migrating database from Version 7.0 and ab… 78Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio… Deploying RSA Authenticator 6.2.2 for Windows Using DISM