RSA Authentication Manager 8.1 SP1 On Demand Authentication requires that the initial PIN be set in the Self-Service Console fails because there is no PIN yet
Originally Published: 2016-08-02
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 SP1 and later
Issue
- Once the user is enabled for ODA, he cannot use the Self Service Console (SSC) to set his PIN because the SSC is prompting for a PIN after the user enters his password.
- As shown here, the Self-Service Console (SSC) logon screen requests Jay's user ID and password.
- The SSC then prompts Jay to enter an existing PIN rather than asking him to create a new PIN.
- Logon fails because a PIN is not set yet. Using a blank PIN or a PIN of 0000 also fails.
- In the Security Console, the enable ODA options show a choice between:
- Require user to setup the PIN through RSA Self-Service Console
- System generate initial PINs for selected users and export them to a file
- The option of system generated initial PIN only worked in Authentication Manager 7.1. All the Authentication Manager 8.1 systems here show that the option is:
Set initial PIN to [ ] (Pin needs to be communicated to user)
- This works if we use the System Generate PINs option. We download the file, logon to the SSC with a password, enter the PIN, then create a new PIN.
- If we select Require user to setup the PIN, and the user logs on to the Security Console, he is prompted to enter a PIN, even though Security Console says PIN not set. Nothing works and the user sees a message of either logon failed or if the PIN is blank, that the field is required
Cause
Resolution
- Manually set ODA user PINs in the Security Console or with the Authentication Manager Bulk Administration (AMBA) tool; or
- Change the Self-Service logon requirements to not enforce an ODA logon, either by removing it completely or by making it optional with the OR operator (that is, /).
Workaround
- Generate PINs for the users.
- Communicate the PINs in a secure manner to the end users.
Related Articles
Unable to set credentials or configure RSA SecurID Appliance 350 iDRAC configuration 175Number of Views Reset the token PIN in the RSA Authentication Manager 8.x Self-Service Console when the existing PIN is forgotten 403Number of Views REMINDER: 1 WEEK LEFT TO COMPLETE UPGRADE WHEN USING RSA CAS AND AVOID SERVICE DISRUPTION 29Number of Views REMINDER: 3 WEEKS LEFT TO COMPLETE UPGRADE WHEN USING RSA CAS AND AVOID SERVICE DISRUPTION 48Number of Views Immediate Next Token Code (NTC) error received for some user logins in RSA Authentication Manager 8.x 483Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?