On-Demand Authentication with an Authentication Agent or a RADIUS Client
Using an on-demand tokencode requested through an authentication agent or RADIUS client differs from the same process when using a tokencode requested through the Self-Service Console, or an RSA SecurID hardware or software token. In each case, the authentication agent prompts the user to enter a User ID and passcode. However, with an on-demand tokencode, the following process occurs:
The user accesses a protected resource, and the agent prompts the user for a User ID and passcode.
The user enters his or her User ID and, at the passcode prompt, an on-demand authentication (ODA) PIN, not passcode.
When a user who is enabled for the on-demand tokencode service enters an ODA PIN at the passcode prompt, AM recognizes that the user is actually making a request for an on-demand tokencode.
AM sends a tokencode to the user.
The authentication agent prompts the user to enter the next tokencode.
The user enters the received on-demand tokencode.
RSA recommends that you inform your users that they cannot simply follow the prompts. Some agents may support changing the prompts to make this less confusing, although this only works if you have an ODA-only user population.
Additionally, if a user cancels out of the next tokencode prompt or waits too long to enter the on-demand tokencode, the tokencode can still be used (with the PIN) to authenticate. For example, the user can attempt to authenticate again, and when the authentication agent or RADIUS client prompts the user for the passcode, the user may enter the PIN and on-demand tokencode as the passcode and successfully authenticate.
Related Articles
RADIUS Clients 115Number of Views Migration from Authentication Manager 7.1 SP4 to 8.1 SP1 migrates RADIUS Client associated agents but not the RADIUS clients 45Number of Views Add a RADIUS Client 52Number of Views Creating agent shows as RADIUS client agent in authentication agents. 86Number of Views Add a RADIUS Client Agent 170Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process