How to Assign a Fixed Passcode to a User in RSA Authentication Manager
11 hours ago
Originally Published: 2019-05-01
Article Number
000049407
Applies To
  • Product: RSA SecurID
  • Component: RSA Authentication Manager
  • Version: 8.x
Issue

A fixed passcode allows a user to authenticate without a hardware or software token. This is typically used as a temporary measure when a user's token is lost, damaged, or pending replacement.

Prerequisites:

  • Access to the RSA Authentication Manager Security Console with Help Desk Administrator or Super Admin privileges
  • The username of the user who requires a fixed passcode

CAUTION: Fixed passcodes bypass two-factor authentication. Remove this setting as soon as the user receives a new token.

Tasks
  1. From the Security Console navigate to Identity > Users Manage Existing.
  2. Search for the user to whom you wish to assign the fixed passcode.
  3. When your search results come back, click on the context arrow next to the user ID and choose Authentication Settings.
  4. Check the option to allow authentication with a fixed passcode.
  5. When prompted create a fixed passcode, such as 87654321.  Provide this to your end user.
  6. When the user next authenticates the user should enter their user ID then the passcode of 87654321.  To the Authentication Manager server, this passcode is in New PIN Mode and will prompt the user to create a new PIN.
  7. At the prompt, they should enter whatever they wants for a fixed passcode, let's say 12345678.
  8. They will see a prompt to wait for the tokencode to roll and enter the PIN.  The interface does not know the user is using a PIN + tokencode or fixed passcode so it just mentions a PIN.  Ignore that.  The user does not need to wait, just enter the fixed passcode created in step 7.  Do not use the PIN associated to any expired token.  Now when the user authenticates, they use their user ID and just this fixed passcode.  

Fixed passcodes are less secure since they are not two factor authentication.  Once your end user receives a new hardware or software token, please go through steps 1 - 4 again, removing the ability to use a fixed passcode.

Resolution

Part 1 — Administrator: Enable Fixed Passcode 

 

  1. Log in to the RSA Authentication Manager Security Console.
  2. Navigate to Identity > Users > Manage Existing. 
  3. Search for the user who requires a fixed passcode. 
  4. In the search results, click the context arrow next to the user's ID and select Authentication Settings. 
  5. Enable the option Allow Authentication with Fixed Passcode. 
  6. When prompted, create a temporary fixed passcode (for example: 87654321). 
  7. Securely provide this temporary passcode to the end user. 

NOTE: Do not use a PIN associated with an expired token as the fixed passcode. 

 

Part 2 — End User: Set a Personal Fixed Passcode 

 

  1. At the login prompt, enter your User ID and the temporary passcode provided by your administrator (for example: 87654321). 
  2. The system will enter New PIN Mode and prompt you to create a new PIN. This prompt uses the word "PIN" — this is expected behavior. You are setting your personal fixed passcode, not a token PIN. 
  3. Enter a new personal fixed passcode of your choice (for example: 12345678). 
  4. If prompted to wait for the tokencode to roll, ignore this message — enter your new fixed passcode immediately. 

CAUTION: Fixed passcodes replace two-factor authentication and are less secure. This should only be used as a temporary measure. 

 

Verification 

The user can now authenticate using their User ID and the personal fixed passcode they created. Confirm by having the user log in successfully. 

 

Removing the Fixed Passcode 

Once the user receives a new hardware or software token, repeat Steps 1–5 in the Admin section above and disable the fixed passcode option. 

Notes
  • Security Risk: Fixed passcodes are single-factor authentication. They should only be used as a temporary measure. Revoke access as soon as the user is issued a new token.

  • New PIN Mode Behavior: When the user first logs in with the administrator-assigned temporary passcode, RSA Authentication Manager places the account in New PIN Mode. The interface displays PIN-related prompts — this is expected and does not indicate an error.

  • Expired Token PINs: Do not use a PIN from an expired token as the fixed passcode. This may cause authentication failures.

  • Removing Fixed Passcode Access: Once the user's new token is ready, return to Identity > Users > Manage Existing > Authentication Settings and disable the fixed passcode option to restore two-factor authentication.

 

For a step-by-step walkthrough, please refer to the following video: How to Assign a Fixed Passcode to a User in RSA Authentication Manager