Exporting a set of One Time Tokencodes from RSA Authentication Manager Self-service Console
Originally Published: 2018-09-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
- Users can export a set of One Time Tokencodes from the Self-Service Console for authentication without contacting the administrator. This allows users to authenticate if they have lost or misplaced their token.
- The user must be within the network perimeter to use the emergency tokencodes.
Tasks
Enable Self-Service Features
- From the Security Console, navigate to Setup > Self-Service Settings.
- On the Settings page, under Customization, click Enable or Disable Self-Service Features.
- Select the following features to Enable and set display options:
- Enable provisioning features
- Display log on section
- Display troubleshoot inks
- Display token is temporarily unavailable or misplaced option
- Click Save.
Set option to allow user to place token in emergency access mode
- In the Security Console, navigate to Setup > Self-Service Settings.
- Click Manage Authenticators.
- In the Emergency Access Tokencode Settings section, select Allow user to place token in emergency access mode. And select Set of One Time Tokencode and the number of codes to be displayed.
- In the Emergency Access Tokencode Settings for Temporarily Unavailable Tokens section, use the Emergency Access Tokencode Lifetime field to enter the length of time you want the emergency access tokencodes to remain active. For example, validity can be chosen based on travel duration.
- Click Save
Resolution
- Login to the Self-Service Console.
- Click on Troubleshoot.
- Select Token is temporarily unavailable or misplaced option and click OK.
- Click on Export to File to save the tokencodes in a .txt file.
Notes
- This solution works for RSA SecurID software and hardware tokens.
- You can only use the Emergency Tokencode once.
- If a SecurID PIN is linked to the token, have end users authenticate with their PIN + Emergency Tokencode.
- If a SecurID PIN is not linked to the token, have end users authenticate with just the Emergency Tokencode that is displayed.
Related Articles
Do the RSA SecurID Access mobile apps support the Time-based One-time Password Algorithm (TOTP)? 192Number of Views How to authenticate with software token for the first time 13Number of Views How to set a new PIN for RSA SecurID Tokens in RSA Authentication Manager 8.6 or later using NTRadPing Utility 135Number of Views Status pages very slow on one of the two appliances in a cluster 19Number of Views Publishing RSA SecurID Access changes for the first time fails after making initial configuration 70Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?