Can RSA SecurID tokens exist in more than one RSA Authentication Manager deployment?
Originally Published: 2019-09-13
Last Modified: 2026-05-14
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4.0
Issue
Resolution
It is technically possible to import the token XML record into different RSA Authentication Manager primary instances; however, it is not recommended for the following reasons:
- Hardware token seed records existing in multiple Authentication Manager deployments put each Authentication Manager deployment at risk. Each Authentication Manager deployment where the token record has been imported knows the same token code being displayed on the token and this could lead to compromising each Authentication Manager deployment.
- PIN management for the token may be confusing for the end user as the end user would have to ensure they create and use the same PIN for the different Authentication Manager deployments.
- RSA Authentication Manager is a time synchronous solution and the token records have a clock offset value to ensure the end user can always authenticate in an Authentication Manager deployment. Should the same token exist in another Authentication Manager deployment, there is no guarantee this token record in the other Authentication Manager deployment will have the same clock offset value and there is a likelihood that the token will authenticate in one Authentication Manager deployment but not the other or vice versa.
A better approach would be to set up a trusted realm (either a one-way or two-way trust) between the Authentication Manager deployments. Detailed information on Trusted Realms and related tasks can be found on RSA Link.
Related Articles
When approval activities are grouped by category, they auto-complete when one of the items is rejected in RSA Identity Gov… 95Number of Views Installation fails with 'unzip: cannot find zipfile directory in one of /tmp/aveksa/packages/<filename.zip>' error in RSA … 56Number of Views How to install one RSA SecurID software token on multiple devices 638Number of Views 'One or more attributes used in Join Condition has duplicate values' error during unification in RSA Identity Governance &… 124Number of Views Limiting users to one token per user ID in RSA Authentication Manager 8.x 135Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?