- Product: RSA SecurID
- Component: RSA Authentication Manager
- Version: 8.x
A fixed passcode allows a user to authenticate without a hardware or software token. This is typically used as a temporary measure when a user's token is lost, damaged, or pending replacement.
Prerequisites:
- Access to the RSA Authentication Manager Security Console with Help Desk Administrator or Super Admin privileges
- The username of the user who requires a fixed passcode
CAUTION: Fixed passcodes bypass two-factor authentication. Remove this setting as soon as the user receives a new token.
- From the Security Console navigate to Identity > Users > Manage Existing.
- Search for the user to whom you wish to assign the fixed passcode.
- When your search results come back, click on the context arrow next to the user ID and choose Authentication Settings.
- Check the option to allow authentication with a fixed passcode.
- When prompted create a fixed passcode, such as 87654321. Provide this to your end user.
- When the user next authenticates the user should enter their user ID then the passcode of 87654321. To the Authentication Manager server, this passcode is in New PIN Mode and will prompt the user to create a new PIN.
- At the prompt, they should enter whatever they wants for a fixed passcode, let's say 12345678.
- They will see a prompt to wait for the tokencode to roll and enter the PIN. The interface does not know the user is using a PIN + tokencode or fixed passcode so it just mentions a PIN. Ignore that. The user does not need to wait, just enter the fixed passcode created in step 7. Do not use the PIN associated to any expired token. Now when the user authenticates, they use their user ID and just this fixed passcode.
Fixed passcodes are less secure since they are not two factor authentication. Once your end user receives a new hardware or software token, please go through steps 1 - 4 again, removing the ability to use a fixed passcode.
Part 1 — Administrator: Enable Fixed Passcode
- Log in to the RSA Authentication Manager Security Console.
- Navigate to Identity > Users > Manage Existing.
- Search for the user who requires a fixed passcode.
- In the search results, click the context arrow next to the user's ID and select Authentication Settings.
- Enable the option Allow Authentication with Fixed Passcode.
- When prompted, create a temporary fixed passcode (for example:
87654321). - Securely provide this temporary passcode to the end user.
NOTE: Do not use a PIN associated with an expired token as the fixed passcode.
Part 2 — End User: Set a Personal Fixed Passcode
- At the login prompt, enter your User ID and the temporary passcode provided by your administrator (for example:
87654321). - The system will enter New PIN Mode and prompt you to create a new PIN. This prompt uses the word "PIN" — this is expected behavior. You are setting your personal fixed passcode, not a token PIN.
- Enter a new personal fixed passcode of your choice (for example:
12345678). - If prompted to wait for the tokencode to roll, ignore this message — enter your new fixed passcode immediately.
CAUTION: Fixed passcodes replace two-factor authentication and are less secure. This should only be used as a temporary measure.
Verification
The user can now authenticate using their User ID and the personal fixed passcode they created. Confirm by having the user log in successfully.
Removing the Fixed Passcode
Once the user receives a new hardware or software token, repeat Steps 1–5 in the Admin section above and disable the fixed passcode option.
-
Security Risk: Fixed passcodes are single-factor authentication. They should only be used as a temporary measure. Revoke access as soon as the user is issued a new token.
-
New PIN Mode Behavior: When the user first logs in with the administrator-assigned temporary passcode, RSA Authentication Manager places the account in New PIN Mode. The interface displays PIN-related prompts — this is expected and does not indicate an error.
-
Expired Token PINs: Do not use a PIN from an expired token as the fixed passcode. This may cause authentication failures.
-
Removing Fixed Passcode Access: Once the user's new token is ready, return to Identity > Users > Manage Existing > Authentication Settings and disable the fixed passcode option to restore two-factor authentication.
For a step-by-step walkthrough, please refer to the following video: How to Assign a Fixed Passcode to a User in RSA Authentication Manager
Related Articles
Assign a User an Alias 160Number of Views Assign a replacement RSA SecurID token to a user in RSA Authentication Manager 895Number of Views Assign a Software Token to a User 91Number of Views Assign a Hardware Token to a User 92Number of Views Authentication Manager 'Principal Does Not Possess Authenticator' Error for Users with Multiple IDs 1.58KNumber of Views
Trending Articles
RSA Authentication Manager 8.8 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) Test connection fails from the RSA ID Plus Cloud Access Service and Identity Router to the SecurID Authentication Manager RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager Upgrade Process