How users can generate a temporary emergency access tokencode from RSA Authentication Manager 8.x Self-Service Console
Originally Published: 2018-09-21
Last Modified: 2026-01-14
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
This article explains how users can generate a temporary emergency access tokencode from the RSA Authentication Manager Self-Service Console without contacting their RSA help desk.
This is useful if the end-user has misplaced their token or forgotten to carry their assigned token to their workplace.
Tasks
Configure Self-Service Settings
- From the Security Console, click Setup > Self-Service Settings.
- On the Settings page, select Customization.
- Click Enable or Disable Self-Service Features.
- Enable the following options:
- For Provisioning, enable provisioning features.
- For Log On Section, enable Display Log on Section.
- For Troubleshooting Links, enable Display Troubleshooting links.
- For Set Display Options for Troubleshooting, enable Display Token is temporarily unavailable for misplaced option.

- Click Save.
- In the Security Console, click Setup > Self-Service Settings.
- Select Manage Authenticators.
- In the Emergency Access Tokencode Settings section, select Allow user to place token in emergency access mode.
- In the Emergency Access Tokencode Settings for Temporarily Unavailable Tokens section, use the Emergency Access Tokencode Lifetime fields to enter the length of time you want emergency access tokencodes to remain active.
- When done, click Save.
Resolution
- Login to the Self-Service Console.
- Click Troubleshoot.
- Select the option that the token is temporarily unavailable or misplaced.
- Click OK.
- An emergency access tokencode is generated for the user.
- The user can now use the emergency access tokencode to authenticate. Use the Test Log On button to confirm.
Notes
- The emergency access tokencode can be used more than once if the emergency access tokencode settings are set to Temporary Fixed tokencode (TFT); however a set of On time tokencodes (OTT) is valid once.
- If you have a SecurID PIN, log on with your PIN + the emergency access tokencode.
- If you do not have a SecurID PIN: Use only the emergency access tokencode.
Related Articles
Can a running review be refreshed without losing the completed work in RSA Identity Governance & Lifecycle? 171Number of Views Can the Microsoft Integrated Windows Authentication (IWA) icon be hidden in the RSA SecurID Access Application Portal? 95Number of Views Can archived aveksa.ear files stored in $AVEKSA_HOME/archive be deleted in RSA Identity Governance & Lifecycle? 140Number of Views How to verify that RSA Authentication Agent for Windows can perform challenge user lookups across different Active Directo… 485Number of Views Can I change the email associated with my RSA Community account if my company changes its name or is acquired? 163Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?