Exporting a set of One Time Tokencodes from RSA Authentication Manager Self-service Console
Originally Published: 2018-09-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
- Users can export a set of One Time Tokencodes from the Self-Service Console for authentication without contacting the administrator. This allows users to authenticate if they have lost or misplaced their token.
- The user must be within the network perimeter to use the emergency tokencodes.
Tasks
Enable Self-Service Features
- From the Security Console, navigate to Setup > Self-Service Settings.
- On the Settings page, under Customization, click Enable or Disable Self-Service Features.
- Select the following features to Enable and set display options:
- Enable provisioning features
- Display log on section
- Display troubleshoot inks
- Display token is temporarily unavailable or misplaced option
- Click Save.
Set option to allow user to place token in emergency access mode
- In the Security Console, navigate to Setup > Self-Service Settings.
- Click Manage Authenticators.
- In the Emergency Access Tokencode Settings section, select Allow user to place token in emergency access mode. And select Set of One Time Tokencode and the number of codes to be displayed.
- In the Emergency Access Tokencode Settings for Temporarily Unavailable Tokens section, use the Emergency Access Tokencode Lifetime field to enter the length of time you want the emergency access tokencodes to remain active. For example, validity can be chosen based on travel duration.
- Click Save
Resolution
- Login to the Self-Service Console.
- Click on Troubleshoot.
- Select Token is temporarily unavailable or misplaced option and click OK.
- Click on Export to File to save the tokencodes in a .txt file.
Notes
- This solution works for RSA SecurID software and hardware tokens.
- You can only use the Emergency Tokencode once.
- If a SecurID PIN is linked to the token, have end users authenticate with their PIN + Emergency Tokencode.
- If a SecurID PIN is not linked to the token, have end users authenticate with just the Emergency Tokencode that is displayed.
Related Articles
How does FSM handle a user who is a member of two groups? 1Number of Views Enable Identity Confirmation Methods for a Risk-Based Authentication Policy 4Number of Views How to authenticate with software token for the first time 13Number of Views RSA DLP Datacenter Scanning of UNIX File Servers 2Number of Views Publishing RSA SecurID Access changes for the first time fails after making initial configuration 70Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?