RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
- How to change the failed authentication thresholds.
- Change Next Tokencode threshold.
- Change Lockout policy.
To change the Next Tokencode threshold for failed authentications, open the Security Console and identify the Token Policy assigned to the Security Domain you want to alter. Keep in mind that a policy can be assigned to more than one Security Domain and that a change to the policy will affect all Security Domains to which the policy is assigned. Go to Administration->Security Domains->Manage Existing. The existing Security Domains are listed and each can be viewed to show the currently assigned policies.
Once you have identified the Token Policy assigned to the Security Domain you want to alter, go to Authentication->Policies->Token Policies->Manage Existing. Click the policy you want to change and click Edit. In the SecurID Token Policy Basics section, change the value for "Require next tokencode after X incorrect passcodes" to the desired value. Click Save. The policy change is immediate.
To change the lockout threshold for failed authentications, open the Security Console and identify the Token Policy assigned to the Security Domain you want to alter. Keep in mind that a policy can be assigned to more than one Security Domain and that a change to the policy affects all Security Domains to which the policy is assigned. Go to Administration->Security Domains->Manage Existing. The existing Security Domains are listed and each can be viewed to show the currently assigned policies.
Once you have identified the Lockout Policy assigned to the Security Domain you want to alter, go to Authentication->Policies->Lockout Policies->Manage Existing. Click the policy you want to change and click Edit. In the Parameters section, change the value for "Lock accounts after X consecutive failed authentications with X days", Click Save. The policy change is immediate.
Related Articles
How to change the RADIUS authentication port on Authentication Manager 8.1 73Number of Views How to change the explicit Change Request (CR) name to include the CR details in name section in RSA Identity Governance a… 86Number of Views Default token policy change prompts every user to change their PIN in RSA Authentication Manager 8.x 232Number of Views RSA Identity Governance and Lifecycle migration script insertMigrationReportDefinitions.sh fails with error ORA-01017: tab… 198Number of Views How to change RSA SecurID token policies to require 6-character or 8 character PINs 212Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide