RSA Authentication Manager-Authentication method failed, passcode format error for all software tokens
Originally Published: 2016-06-06
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
All RSA SecurID software token users suddenly cannot authenticate. The following error is displayed at the authentication prompt across all authentication methods:
Authentication method failed, passcode format error
- In Authentication Manager 8.x and later, the following error is displayed for all software tokens, but hardware tokens and fixed passcodes work:
Observable symptoms:
- All software token users receive the above error when attempting to authenticate
- Hardware tokens and fixed passcodes continue to work normally
- The error occurs across both native SecurID agents and RADIUS clients with their associated agents
- RSA SecurID software tokens on end-user devices fail to resynchronize in the Security Console
ℹ️ NOTE: If only some users are affected, this article may not apply. This issue affects all software tokens simultaneously.
Cause
An administrator accidentally triggered a bulk redistribution of all assigned software tokens, which regenerated the seed value for every token. This commonly happens when a distribution job is submitted without specifying token selection criteria, causing all assigned tokens to be selected automatically.
Once the new seed values are issued, the Authentication Manager server expects authentication using the newly generated tokencodes. Since end users still have the old token installed on their devices, all authentication attempts fail until users import the new token data.
ℹ️ NOTE: Authentication Manager displays the following warnings before this action completes. If these warnings are dismissed without careful review, the bulk redistribution proceeds:
This job generates new token seeds for these tokens. Existing users of these tokens will no longer be able to authenticate. Users must import the new token data before they can authenticate.
Resolution
⚠️ CAUTION: There is no rollback option once software tokens have been redistributed. Choose one of the two resolution options below based on your environment.
Option A: Distribute New Token Seeds to End Users (Use this option if no recent backup is available or losing recent data is not acceptable.)
Step 1: Export the newly generated token seed files from the Security Console.
Step 2: Distribute the new token seed files to all affected end users.
Step 3: Instruct each user to import the new token data on their device and test authentication.
Step 4 — Verify: Confirm that affected users can successfully authenticate using their updated
software token.
Option B: Restore Authentication Manager from Backup (Use this option only if a pre-redistribution backup is available and data loss since that backup is acceptable.)
⚠️ CAUTION: Restoring from backup will overwrite the current system and permanently delete all data changes made since the backup was taken. Take a backup of the current system state before proceeding.
Step 1: Navigate to Maintenance > Backup and Restore > Backup Now in the Operations Console to take a backup of the current system state.
Step 2: Navigate to Maintenance > Backup and Restore > Restore in the Operations Console.
Step 3: Select the correct pre-redistribution backup file carefully. Confirm this is the backup taken before the token redistribution occurred.
Step 4: Initiate the restore and wait for it to complete.
Step 5 — Verify: Confirm that software token users can successfully authenticate with their original tokens after the restore completes.
Workaround
⚠️ This is a preventative workaround — it does not resolve the issue after it has already occurred. If the bulk redistribution has already taken place, refer to the Resolution section above.
What this workaround achieves: Taking a backup immediately before performing any bulk software token distribution ensures that a recovery point exists. If the redistribution causes widespread authentication failure, you can restore the system to its pre-redistribution state using Option B in the Resolution section.
What this workaround does NOT fix: It does not prevent the bulk redistribution from occurring. It only ensures a recovery option is available if the issue happens.
Step 1: Before performing any bulk software token distribution, navigate to Maintenance > Backup and Restore > Backup Now in the Operations Console.
Step 2: Wait for the backup to complete and confirm it was successful.
Step 3: Proceed with the software token distribution only after the backup has been confirmed.
Notes
Related Articles
Error 'Authentication method failed passcode format error' 501Number of Views Reporting on SecurID software tokens with software token lifetime extension in RSA Authentication Manager 8.x 967Number of Views How to generate a report to list all users with a fixed passcode in Authentication Manager 8.x 453Number of Views Using alphanumeric PINs with RSA SecurID Software Tokens and RSA Authentication Manager 8.x 50Number of Views Details on RSA SecurID tokens and RSA Authentication Manager licenses 1.31KNumber of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process
Don't see what you're looking for?