How to set emergency access tokencode lifetime for permanently lost or broken RSA SecurID tokens
2 years ago
Originally Published: 2014-01-30
Article Number
000040536
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue

This article explains how to set emergency access tokencode lifetime for permanently lost or broken RSA SecurID tokens.

Resolution

In the Security Console,

  1. Click Setup > Self-Service Settings.
  2. Click Manage Authenticators.
  3. In the Emergency Access Tokencode Settings for Permanently Lost or Broken Tokens section, use the Emergency Access Tokencode Lifetime fields to enter the length of time for which the emergency access tokencodes are to remain active.  (The default value is set to 7 days)
User-added image
  1. Choose an option for if token becomes available.   Authentication Manager take one of the following actions:
    • Deny authentication,
    • Allow authentication and disable online emergency tokencodes, or
    • Allow authentication with the token only after the emergency access tokencode lifetime has expired.
  2. Click Save when done.
Notes
Note: Kindly note that the emergency access code can't be used when the software/hardware token lifetime expires as the authentications will be denied as the token it self reached its end of life.