How to setup On-Demand Authentication (ODA) in RSA Authentication Manager 8.x
Originally Published: 2014-05-07
Last Modified: 2026-01-14
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Cause
Resolution
Before completing the steps below, ensure you have successfully configured on-demand tokencode delivery. For more information see the online help topic entitled Configure On-Demand Tokencode Delivery.
You must have an Enterprise License for On-Demand Authentication or Risk Based Authentication (RBA). Confirm this in the Security Console under Setup > License Status.
Enable ODA for the user
- Search for the user in the Security Console under Identity > Users > Manage Existing.
- When the user in question is returned, click on the context arrow next to the user name and select SecurID Tokens.
- Hardware and software tokens assigned to the user are listed at the top of the page. Scroll down to the section labeled On-Demand Authentication (ODA).
- Check the option to enable the user for on-demand authentication.
- Optionally, you can set an expiration for this on-demand token.
- For Send On-Demand Tokencodes, ensure the correct attribute is set and update if needed.
- For the attribute, enter the email address or mobile number.
- For Associated PIN, choose to require the users to set the PIN through the Self-Service Console or set the initial PIN for the user.
- When done, click Save.
Using the On-Demand Token
- The user opens a browser window, VPN client or Windows login page and accesses the company web portal or protected resource (also known as an authentication agent).
- When prompted, the user enters their user ID and PIN
- A one time tokencode is sent to the users mobile phone via SMS or email.
- The user enters the tokencode into the browser/login page.
- The user gains access to the protected resource
You do not need to enable ODA or ODT on an agent. Check the RSA Ready implementation Guides for support on partner platforms with either SecurID or RADIUS protocol.
Notes
ODA Tokencode lifetime: The lifetime of an on-demand tokencode in RSA Authentication Manager is set by your administrator and it expires after one use or within the lifetime specified.
Related Articles
How to set cookie expiration times 25Number of Views How to reset table views to their original factory-set (OOTB) defaults in RSA Identity Governance & Lifecycle 33Number of Views Authentication Manager 8.x Quick Setup Access Code Not Displayed After Appliance Deployment 556Number of Views RSA Authentication Manager 8.1 Quick Setup Fails with "Failed to Attach Replica Instance" 1.86KNumber of Views "No configured interfaces were detected" error after finishing Quick Setup on a new RSA Authentication Manager 8.4 server 530Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?