RSA MFA Agent for Microsoft Windows Log Events
10 days ago

This page provides the details of the events logged by the RSA MFA Agent for Microsoft Windows in the Windows Event Viewer.

 

For each event category, the corresponding table(s) lists the event ID, severity, and the corresponding message and its parameters. Parameters values appear according to the specific details of each event. For event messages that include parameters, parameters are indicated throughout this page within the message text as <parameter name>.

 

The MFA Agent events are categorized as follows:

  1. Authenticator & General Authentication Events (1000–1021)
  2. Evidence Collection Events (1100–1110)
  3. Windows Authentication Events (1200–1203)
  4. Offline Authentication Events (1300)
  5. Reserve Password Events (1400–1405)
  6. FIDO/Passwordless Authentication Events (6600–6620)
  7. Credential Provider Filter Starting Events (2000–2002)
  8. Windows Agent Service Starting Events (3000–3008)
  9. Offline Authentication Service Starting Events (4000–4016)
  10. Authentication Server Service Starting Events (5000–5004)
  11. Test Authentication Tool Starting Events (9000)
  12. Azure Authentication Starting Events (8000)
  13. Passwordless Auth Services Messages Events (7000–7008)

 

Note: This page lists the events for the RSA MFA Agent version 2.5 and earlier. The list of events is updated with each Agent release.

 

Authenticator & General Authentication Events (1000–1021)

Event IDSeverityMessage
1000Exception(Reserved for exceptions) 
1001Success AuditSuccessful authentication to RSA. User: <username>, Method: <authentication method>
1002Failure AuditUnsuccessful authentication to RSA. User: <username>, Method: <authentication method>
1003InfoAuthentication to RSA canceled by user. User: <username>, Method: <authentication method>
1004ErrorUnsuccessful authentication to RSA Authentication Service. User: <username>, Reason: <reason>
1005Success AuditSuccessful offline authentication. User:  <username>, Method: <authentication method>
1006Failure AuditUnsuccessful offline authentication. User:  <username>, Method: <authentication method>
1007Failure AuditUnsuccessful offline authentication. No offline data available. User:  <username>, Method: <authentication method>
1008InfoOffline authentication canceled by user. User:  <username>, Method: <authentication method>
1009ErrorUnsuccessful authentication to RSA. This computer cannot connect to RSA. 
1010ErrorUnsuccessful authentication to RSA Authentication Service. The policy <policy name> was not found.
1011ErrorUnsuccessful authentication to RSA Authentication Service. The user <username> was not found. 
1012ErrorUnsuccessful authentication to RSA Authentication Service. The user <username> has to install and register the RSA Authenticator app.
1013ErrorUnsuccessful authentication to RSA Authentication Service. The user <username> cannot authenticate with any methods in the policy <policy name>.
1014ErrorUnsuccessful authentication to RSA Authentication Service. The user <username> is disabled in RSA.
1015ErrorUnsuccessful authentication to RSA Authentication Service. The user <username> is denied access by the policy <policy name>.
1016Failure AuditUnsuccessful authentication for user: <username>. Passcode can not be reused.
1017InfoUser <username> does not need to perform additional authentication based on the Cloud Access Service access policy.
1018InfoThe user <username> was not found, but this computer is configured to not require additional authentication for an unknown user.
1019InfoUser <username> does not need to perform additional authentication. RSA authentication is not enabled on this computer.
1020InfoUser <username> does not need to perform additional authentication based on the Local Authentication Settings Challenge Group policy. 
1021ErrorUnsuccessful authentication to RSA Authentication Service. The policy <policy name> is not supported.

Evidence Collection Events (1100–1110)

Event IDSeverityMessage
1100InfoSystem attribute collection is enabled on this computer.
1101InfoSystem attribute collection is disabled on this computer.
1102Success AuditSent system attributes from this computer for the user <username> to RSA.
1103Failure AuditUnsuccessful collection of system attributes from this computer for the user <username>.
1104Success AuditSuccessful collection of location from this computer for user <username>.
1105Failure AuditUnsuccessful collection of location from this computer for user <username> within the specified timeout.
1106Success AuditCollected IP address for user <username>.
1107Failure AuditUnsuccessful collection of IP address from this computer for user <username>.
1108InfoLocation collection timeout value is configured to <timeout value> seconds.
1109InfoSystem can access location data because location service is on for this computer for user <username>.
1110WarningSystem cannot access location data for this computer for user <username>.

Windows Authentication Events (1200–1203)

Event IDSeverityMessage
1200InfoPassword credentials collected. User: <username> Domain: <domain>
1201Success AuditAuthentication to Windows succeeded.
1202Failure AuditAuthentication to Windows failed.
1203WarningWindows Password has Expired.

Offline Authentication Events (1300)

Event IDSeverityMessage
1300InfoOffline authentication is disabled on this computer.

Reserve Password Events (1400–1405)

Event IDSeverityMessage
1400Success AuditSuccessful reserve password authentication. User: <username>, Method: <authentication method>
1401Failure AuditUnsuccessful reserve password authentication. User: <username>, Method: <authentication method>
1402InfoReserve password authentication canceled by user. User: <username>, Method: <authentication method>
1403InfoReserve password is disabled on this computer.
1404ErrorReserve password length error.
1405ErrorIncorrect hash format. Review your reserve password in the policy settings.

FIDO/Passwordless Authentication Events (6600–6620)

Event IDSeverityMessage
6600ErrorFIDO_RP_ID is not configured. Cannot proceed with FIDO authentication.
6601ErrorUnsuccessful authentication to the Cloud Access Service. The user <username> must register the FIDO authenticator.
6602ErrorUnsuccessful authentication to the Cloud Access Service. User <username> credentials are invalid for primary authentication using FIDO security key.
6603ErrorUnsuccessful authentication to the Cloud Access Service. Security key is not supported.
6604ErrorUnsuccessful authentication to the Cloud Access Service. PIN is not set for the security key.
6605ErrorUnsuccessful authentication to the Cloud Access Service. PIN is locked after too many unsuccessful sign-in attempts. User <username> must reset the security key and re-register.
6606ErrorUnsuccessful authentication to the Cloud Access Service. Security key does not contain valid credentials for user <username>.
6607ErrorUnsuccessful authentication for user: <username>. Required Configuration not found to complete FIDO authentication.
6608ErrorUnsuccessful authentication for user: <username>. Cloud Access Service is not reachable and Virtual Smart Card is not present for the user.
6609Success AuditSuccessful Offline Primary FIDO Authentication for user: <username>.
6610WarningUser <username> is permitted to authenticate using Windows password and MFA, if configured. User must register the FIDO authenticator with Cloud Access Service before attempting passwordless authentication.
6611WarningUser <username> is permitted to authenticate using Windows password and MFA, if configured. User must set the FIDO PIN for the security key before attempting passwordless authentication.
6612WarningUser <username> is permitted to authenticate using Windows password and MFA, if configured. Security key is locked after too many unsuccessful sign-in attempts. User must reset the security key and re-register.
6613WarningUser <username> is permitted to authenticate using Windows password and MFA, if configured. User's security key contains invalid credentials. User must re-register security key with Cloud Access Service.
6614ErrorFIDO unknown exception
6615ErrorFIDO Exception
6616ErrorTPM is not present on the machine.
6617InfoDisabling passwordless credential provider and enabling password credential provider.
6618ErrorTransactional Error occurred when communicating with Security Key. Re-insert your security key and try again.
6619InfoThe user <username> was not found, but this computer is configured to not require passwordless authentication for an unknown user.
6620Success AuditAccess attribute updated successfully for user <username>.

Credential Provider Filter Starting Events (2000–2002)

 

Event IDSeverityMessage
2000InfoFiltered a Credential Provider. Name: <name>, CLSID: <class ID>
2002WarningUnable to filter a Credential Provider because it was not in the list of available credential providers. Name: <name>, CLSID: <class ID>

Windows Agent Service Starting Events (3000–3008)

 

Event IDSeverityMessage
3000ErrorAn RSA Settings group policy is improperly configured on this computer. Policy name: <policy name>, Configured setting: <setting>
3001InfoThe service started successfully
3002InfoThe service stopped successfully
3003InfoA service component has started: <service name>
3004InfoA service component has stopped: <service name>
3005ErrorA service component did not start: <service name> Error: <error>
3006ErrorThe service encountered an error. Error: <error>
3007InfoThe service is starting
3008InfoA service component is starting: <service name>

Offline Authentication Service Starting Events (4000–4016)

 

Event IDSeverityMessage
4000InfoDeleted all offline data for user <username>. The offline data is no longer valid for use on this device.
4001Success AuditDownloaded <number of offline days> days of offline data for user <username>.
4002Success AuditDownloaded offline eac data for user <username>.
4003Failure AuditFailed to download offline data for user <username>. RSA returned <error>.
4004Failure AuditFailed to download offline eac data for user <username>. RSA returned <error>.
4005InfoDeleted all offline data for users on this computer.
4006InfoDeleted offline eac data for user <username>.
4007Success AuditDeleted all offline data for local user accounts on this computer.
4008Success AuditDownloaded offline metadata for agent <client ID>.
4009Failure AuditFailed to download offline metadata for agent <client ID>. RSA returned <offline metadata response>.
4010Success AuditDownloaded offline metadata for user <username>.
4011Failure AuditFailed to download offline metadata for user <username>. RSA returned <offline metadata response>.
4012Failure AuditUnsuccessful offline authentication. The user <username> reached maximum number of authentication failure limit
4013Failure AuditUnsuccessful offline authentication for user: <username>. Passcode can not be reused.
4014Success AuditSuccessful offline authentication. User: <username>, Method: <authentication method>
4015Failure AuditUnsuccessful offline authentication. User: <username>, Method: <authentication method>
4016Failure AuditFailed to download offline data for user. WPI certificate not available. Please contact Administrator.

Authentication Server Service Starting Events (5000–5004)

 

Event IDSeverityMessage
5000ErrorFailed to retrieve a policy. Policy name: <policy name>. Exception: <exception message>
5001ErrorAn error occurred while Initializing servers. Check configuration.
5002ErrorAn error occurred while Initializing servers. Exception: <exception message>
5003ErrorUpdated server status to down. Server url: <server URL>
5004ErrorUpdated server status to down. Exception: <exception message>

Test Authentication Tool Starting Events (9000)

Event IDSeverityMessage
9000WarningRSA authentication is not enabled on this computer. User <username> is allowed to test authentication.

Azure Authentication Starting Events (8000)

Event IDSeverityMessage
8000ErrorFailed to retrieve a policy. Policy name: <policy name>. Exception: <exception message>

Passwordless Auth Services Messages Events (7000–7008)

Event IDSeverityMessage
7000Success AuditVirtual smart card created successfully for user <username>. Reader name - <reader name>, Instance Id - <instance ID>.
7001Failure AuditVirtual smart card creation unsuccessful for user <username>.
7002Success AuditVirtual smart card reader terminated with instance Id - <instance ID>.
7003Failure AuditVirtual smart card reader termination unsuccessful with instance Id - <instance ID>.
7004Success AuditSignin certificate enrolled successfully for user <username>.
7005Failure AuditSignin certificate enrollment unsuccessful for user <username>.
7006Failure AuditSmart card creation unsuccessful. Trusted Platform Module is not ready.
7007Failure AuditSmart card creation unsuccessful. Trusted Platform Module is not found.
7008Failure AuditSmart card readers reached maximum limit. No new smart card can be created.