Disable Double MFA Authentication Attempts During RDP and Machine Login
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: MFA Agent
RSA Version/Condition: 2.3.x
Issue
The customer wants to allow only one MFA Agent authentication attempt when logging in to the machine and avoid triggering an MFA Agent prompt during RDP sessions.
Resolution
Enable Policy for Remote Desktop Applications Without RSA Authentication
-
Edit the GPO located under:
Computer Configuration → Administrative Templates → RSA Desktop → Local Authentication Settings -
Enable the policy:
Specify remote desktop applications that do not require RSA authentication -
Add the following applications to Fully-Qualified Application Path(s):
C:\Windows\System32\mstsc.exe,C:\Windows\System32\CredentialUIBroker.exe,C:\Program Files (x86)\Microsoft\Remote Desktop Connection Manager\RDCMan.exe
Related Articles
Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … 1.29KNumber of Views Maximum number of incorrect login attempts for RSA Authentication Manager Operations Console administrator 192Number of Views How to disable or enable the Other Users tile on the logon screen on a Windows machine protected by RSA Authentication Age… 512Number of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.15KNumber of Views Successful SSH login attempts are not logged in /var/log/messages in Authentication Manager prior to 8.4 39Number of Views
Don't see what you're looking for?