Three incorrect token passcodes on RSA Authentication Agent 7.4.x for WIndows causes the user's Active Directory account to lock
Originally Published: 2019-02-14
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4.x,, 7.3.3
Platform (Other): Windows
Issue
If we enter three incorrect passcodes the AD User account will become locked in AD. This behavior is only seen on a Windows agent, other agents do not lock AD accounts. This also occurs whether or not the Authentication Manager Identity source User Enable Status on the external Identity Source (AD) is configured as manage in both directory and AM or manage only in directory.
It was to our understanding that a lockout of SecurID was fully independent from the AD (Domain) account and that one cannot effect the other.
Cause
Enabling this policy would make the RSA agent respect Local or AD lockout policy settings, which in this case were set to three failures to produce a lockout.
Resolution
The Do Not Preserve History (default) mode enables display of descriptive authentication failure messages to users during log on but does not preserve failed authentication history for display at successful log on, when Windows is configured to show last interactive log on information.
Workaround
Related Articles
Alerting Issue in UI in RSA Web Threat Detection 5.1.0.7 Custom Key 7Number of Views Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1 275Number of Views High CPU utilization caused by Webservice calls embedded in request forms in RSA Governance & Lifecycle 49Number of Views A "Page Not Found" error is displayed after logging in to the RSA Community, myRSA, or the RSA Partner Portal 25Number of Views Disable a User Account 18Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?