Configure Handling of Incorrect Passcodes
Occasionally, a user mistakenly enters a series of incorrect passcodes before entering the correct passcode. You can configure how AM handles these situations.
You can allow users to enter an unlimited number of incorrect passcodes, or limit the number of incorrect passcodes a user is allowed to enter. If you set a limit, when the limit is exceeded and followed by a correct passcode, users are prompted to enter the next tokencode that displays on their token.
This guards against situations in which an unauthorized person attempts to guess a passcode. In such a case, even if the person guessed a correct passcode, he or she is prompted for the next tokencode and given only one chance to enter it correctly. If the person enters the next tokencode incorrectly, the user account to which the token belongs is locked.
This behavior is controlled by the OTP authenticator policy assigned to individual security domains. To change this setting you must edit the policy.
Procedure
In the Security Console, click Authentication > Policies > Token Policies > Manage Existing.
Use the search fields to find the policy that you want to edit.
From the search results, click the policy that you want to edit.
From the context menu, click Edit.
Under Basics, for Incorrect Passcodes, specify how you want the deployment to respond when a user enters incorrect passcodes.
Click Save.
Related Concepts
Related Articles
Edit Cloud Access Service Connection 94Number of Views How to set up RSA ACE/Agent for UNIX without using the CD-ROM 9Number of Views Domain name is not resolvable from the LWCS box 19Number of Views Add an Administrative Role 24Number of Views Quick Setup Guide - Cloud Access Service POC - Step 4: Add an Access Policy 29Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)