Three incorrect token passcodes on RSA Authentication Agent 7.4.x for WIndows causes the user's Active Directory account to lock
Originally Published: 2019-02-14
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4.x,, 7.3.3
Platform (Other): Windows
Issue
If we enter three incorrect passcodes the AD User account will become locked in AD. This behavior is only seen on a Windows agent, other agents do not lock AD accounts. This also occurs whether or not the Authentication Manager Identity source User Enable Status on the external Identity Source (AD) is configured as manage in both directory and AM or manage only in directory.
It was to our understanding that a lockout of SecurID was fully independent from the AD (Domain) account and that one cannot effect the other.
Cause
Enabling this policy would make the RSA agent respect Local or AD lockout policy settings, which in this case were set to three failures to produce a lockout.
Resolution
The Do Not Preserve History (default) mode enables display of descriptive authentication failure messages to users during log on but does not preserve failed authentication history for display at successful log on, when Windows is configured to show last interactive log on information.
Workaround
Related Articles
Disable an RSA Authentication Manager user account using the Administration API 50Number of Views Adding multiple fulfillment nodes or paths for one item in a workflow in RSA Identity Governance & Lifecycle 16Number of Views Changes to the E-mail Notifications for User Account Changes do not take effect 7Number of Views Can one user account be linked to multiple tokens simultaneously in RSA ACE/Server and RSA Authentication Manager? 52Number of Views RSA Identity Governance and Lifecycle user account table control type in the request form does not list all accounts when … 35Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?