Disable Double MFA Authentication Attempts During RDP and Machine Login
Last Modified: 2026-07-10
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: MFA Agent
RSA Version/Condition: 2.3.x
Issue
The customer wants to allow only one MFA Agent authentication attempt when logging in to the machine and avoid triggering an MFA Agent prompt during RDP sessions.
Resolution
Enable Policy for Remote Desktop Applications Without RSA Authentication
-
Edit the GPO located under:
Computer Configuration → Administrative Templates → RSA Desktop → Local Authentication Settings -
Enable the policy:
Specify remote desktop applications that do not require RSA authentication -
Add the following applications to Fully-Qualified Application Path(s):
C:\Windows\System32\mstsc.exe,C:\Windows\System32\CredentialUIBroker.exe,C:\Program Files (x86)\Microsoft\Remote Desktop Connection Manager\RDCMan.exe
Related Articles
Authentication Issues Using A Third-Party RDP Client And RSA Authentication Agent 7.3.3 for Windows 32Number of Views Set User Expectations for Device Registration and Authentication 209Number of Views Increasing the number of connections from RSA Authentication Agent 7.3.x for Windows to a Windows platform with RDP 63Number of Views Test Web Services Description Language (WSDL) connectivity for RSA Authentication Manager 8.x 225Number of Views Review generation fails with 'ORA-01427: single-row subquery returns more than one row' in RSA Identity Governance & Lifec… 786Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?