Announcing the January 2022 Release of SecurID
2 years ago
Originally Published: 2021-11-04

The January 2022 release of the Cloud Authentication Service is currently available in the ANZ-based Microsoft Azure Cloud. The EMEA-based Microsoft Azure Cloud is expected to receive this update on January 25th, and the US-based Microsoft Azure Cloud is expected to receive this update on January 29th.

Cloud Administration Console URLs Are Changing in January 2022

The Cloud Administration Console URLs for your company are changing to include your company subdomain. For example, if you previously accessed the Console with https://na2.access.securid.com/ and your company subdomain is example, you will now access the Console with https://example.access.securid.com. The Cloud Authentication Service can dynamically redirect your administrative requests to a suitable environment if a problem is detected that affects service availability.

The shared URLs in use prior to January 2022 will remain available for sign-in and administrators will receive a message in the Console reminding them to update bookmarks to use the new URLs. The shared URLs will continue to be supported for at least a year but might not offer all capabilities or perform as well as the new company-specific URLs.

To find the region and service where your Cloud Authentication Service is deployed, sign into the Cloud Administration Console and find the blue hyperlink next to Hello <administrator's name> near the top left of the Dashboard page. You need to know the region and service when checking the Cloud Authentication Service status page, uptime page, and notifications for maintenance and service incidents.

Action Required if You Have a Third-Party Identity Provider Protecting Access to the Cloud Administration Console

If your deployment configured a third-party identity provider (IdP) to protect access to the Cloud Administration Console, the shared console URLs are saved as the SAML Sign-In URL and the Assertion Consumer Service URL. These URLs will continue to be supported after the universal change to company-specific URLs. However, SecurID recommends that you update these URLs to point to the new company-specific URLs for best performance. To view the company-specific URLs, open the Cloud Administration Console and click My Account > Company Settings > Sessions & Authentication tab. The new URLs are automatically provided in the SAML Sign-In URL and Assertion Consumer Service URL fields. Copy these URLs to your IdP configuration.

Whitelisting URLs Accessed by the Identity Router

The repository URLs accessed by the identity router will change to become company-specific. Therefore, make sure any whitelisting you have in place reflects these new URLs. For best practices, we recommend that you whitelist *.securid.com and *.securidgov.com instead.

New and Updated Third-Party Integrations from RSA Ready 

The following integrations were recently completed by RSA or certified by RSA through the RSA Ready Technology Partner Program. For Implementation Guides, see SecurID Access Integrations.

  • Firehydrant.io (new, Cloud Authentication Service) – incident management platform supports SecurID Access MFA via SAML including SSO and Relying Party.
  • goCanvas (new, Cloud Authentication Service) - provides mobile apps and forms for data collection and sharing. Supports SSO or relying party.
  • Juniper Networks JunOS vSRX (new, Authentication Manager) – virtual NGFW supports SecurID Access authentication via Radius with Authentication Manager.
  • McAfee MVISION (new, Cloud Authentication Service) - protects data and stops threats in the Cloud across SaaS, PaaS, and IaaS from a single, cloud-native enforcement point. Supports SSO.
  • Microsoft Office 365 (update, Cloud Authentication Service) – updated CAS support for MFA into Microsoft 365 including SSO and Relying Party.
  • Microsoft Sharepoint 2019 (new, Cloud Authentication Service) – SSO Agent for SecurID Access authentication via SAML.
  • Specops uReset (new, Authentication Manager/Cloud Authentication Service) – self-service password reset supports SecurID Access authentication via REST API.
  • SUSE Rancher (new, Cloud Authentication Service) – unifies Kubernetes clusters to ensure consistent operations, workload management, and enterprise grade security. Supports SSO or relying party.

We would like to remind Technology Partners about the SecurID Authentication API, a REST-based programming interface that allows you to develop clients that process multifactor, multistep authentications through RSA Authentication Manager and the Cloud Authentication Service.

The SecurID Authentication API was released in 2019 and is one of the supported methods to integrate your client applications with the Cloud Authentication Service, in addition to SAML2 and RADIUS. It replaces RSA SecurID Authentication API 8.6 for C and Java to communicate with Authentication Manager. As of June 2021, version 8.6 is now End of Primary Support Level 2, which means there are no hot fixes available and only best effort support is provided.

To remain RSA Ready, all Technology Partners should plan to support the Cloud Authentication Service in your applications by the end of 2022. If you use version 8.6 or older, you may update to the SecurID Authentication API. Documentation and a YAML file (Logon required) are available on RSA Link. Contact SecurID Partner Engineering for questions and technical support, rsapesupport@securid.com.

Removed the Ability to Request a Account Through the Security Console

SecurID no longer supports requesting a account through the Security Console. If you try to request an account, your patch level determines the error message that you receive.

You can continue to use your existing accounts. If you need a new account, call SecurID Sales at 1 800 995 5095.

SecurID 4.0 App is Available!

SecurID 4.0 app for iOS and Android adds cloud-based multifactor authentication to the software token functionality already present in the SecurID 3.0 app. Users have one convenient authenticator to safely sign into their company accounts. This enhancement helps your company move authentication to the cloud and effectively manage a hybrid deployment.  See Announcing the Release of SecurID 4.0 for iOS and Android App.

Announcement