Disable Double MFA Authentication Attempts During RDP and Machine Login
a month ago
Article Number
000073727
Applies To

RSA Product Set: SecurID
RSA Product/Service Type: MFA Agent
RSA Version/Condition: 2.3.x

Issue
The customer wants to allow only one MFA Agent authentication attempt when logging in to the machine and avoid triggering an MFA Agent prompt during RDP sessions.
Resolution

Enable Policy for Remote Desktop Applications Without RSA Authentication

  1. Edit the GPO located under:
    Computer Configuration → Administrative Templates → RSA Desktop → Local Authentication Settings

  2. Enable the policy:
    Specify remote desktop applications that do not require RSA authentication



  3. Add the following applications to Fully-Qualified Application Path(s):

    C:\Windows\System32\mstsc.exe,C:\Windows\System32\CredentialUIBroker.exe,C:\Program Files (x86)\Microsoft\Remote Desktop Connection Manager\RDCMan.exe