Authenticating using emergency access tokencodes containing special characters does not work with RSA Authentication Agent 2.0 for Microsoft AD FS
Originally Published: 2019-02-21
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for AD FS
RSA Version/Condition: 2.0
Issue
The error observed is as follows:
You must enter a passcode
There will be no messages in the real-time authentication activity monitors regarding authentication failure.
Workaround
To edit the token policy,
- Login to Security Console.
- Navigate to Authentication > Policies > Token Policies > Initial Token Policy (or the relevant token policy).
- Click Edit.
- At the bottom of the page under Emergency Access Code Format, make sure the following are checked:
- Include numeric characters
- Include alphabetic characters
- Uncheck the option for Include special characters.
- Click Save.
- Authentication will work fine with letters, numbers or both.
Related Articles
Signed Certificate Management Protocol (CMP) requests do not work in KCA 6.5.1 if certificate's DN contains 'special' char… 3Number of Views Does RCM handle all special characters in email address allowed per the RFC? 11Number of Views What special characters are disallowed in Access Manager user and group names? 26Number of Views Special characters other than '_' and '$' are not allowed for Variables in Account Template Fields in RSA Identity Governa… 71Number of Views Special characters other than '_' and '$' are not allowed for Variables in AFX Connector Mapping Fields in RSA Identity Go… 67Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?