Exporting a set of One Time Tokencodes from RSA Authentication Manager Self-service Console
2 years ago
Originally Published: 2018-09-21
Article Number
000063515
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
  • Users can export a set of One Time Tokencodes from the Self-Service Console for authentication without contacting the administrator. This allows users to authenticate if they have lost or misplaced their token.
  • The user must be within the network perimeter to use the emergency tokencodes.
Tasks
The administrator with the super admin role needs to setup the following on the Authentication Manager primary server:

Enable Self-Service Features

  1. From the Security Console, navigate to Setup > Self-Service Settings.
  2. On the Settings page, under Customization, click Enable or Disable Self-Service Features.
  3. Select the following features to Enable and set display options:
  • Enable provisioning features
  • Display log on section
  • Display troubleshoot inks
  • Display token is temporarily unavailable or misplaced option
User-added image
  1. Click Save.

Set option to allow user to place token in emergency access mode

  1. In the Security Console, navigate to Setup > Self-Service Settings.
  2. Click Manage Authenticators.
  3. In the Emergency Access Tokencode Settings section, select Allow user to place token in emergency access mode. And select Set of One Time Tokencode and the number of codes to be displayed.
User-added image
  1. In the Emergency Access Tokencode Settings for Temporarily Unavailable Tokens section, use the Emergency Access Tokencode Lifetime field to enter the length of time you want the emergency access tokencodes to remain active. For example, validity can be chosen based on travel duration.
User-added image
  1. Click Save
Resolution
Users can login to the Self-Service Console using their password and export a set of One Time Tokencodes for Authentication.
  1. Login to the Self-Service Console.
  2. Click on Troubleshoot.
User-added image
  1. Select Token is temporarily unavailable or misplaced option and click OK.
User-added image
  1. Click on Export to File to save the tokencodes in a .txt file. 
User-added image
Notes
  • This solution works for RSA SecurID software and hardware tokens.
  • You can only use the Emergency Tokencode once.
  • If a SecurID PIN is linked to the token, have end users authenticate with their PIN + Emergency Tokencode.
  • If a SecurID PIN is not linked to the token, have end users authenticate with just the Emergency Tokencode that is displayed.