Tokens distributed using CT-KIP URL used to be imported in SecurID Authenticator 6.x for Windows are sent with activation code via e-mail after automatically/being approved by system/superadmins
Article Number
Applies To
RSA Product/Service Type: Authentication Manager, SecurID Authenticator 6.x for Windows
Issue
1. Desktop PC 4.x
2. SecurID Authenticator for Windows 6.x
Software Token Profiles. However, based on this KB article <Unable to Import SecurID Tokens via CT-KIP URL to the Windows SecurID Authenticator 6.x >, NO activation code is required to import software tokens in SecurID Authenticator for Windows 6.x .
- Email recieved by the user if the token is distributed using delivery method 'CT-KIP URL' and device type 'Desktop PC 4.x' - Old App
- Email recieved by the user if the token is distributed using delivery method 'CT-KIP URL' and device type 'SecurID Authenticator for Windows 6.x' - New App
As per the last 2 images, there is no difference except in the URL as both e-mails contain the activiation code associated with the CT-KIP URL.
Cause
Resolution
Here are the steps:
1. Log on to the security console as a super admin
2. Navigate to Setup > Self-service settings > Provisioning > Edit Workflow policy > Software Token > E-mail Notification Templates
3. You have two options:
a. If you did not do any modifications before to this template, download the attached text file and replace the content of E-mail Notification Templates in the security console with that in the attached text.
b. If you did modification before to this template, Copy the template in a notepad and add those line to the current template above this line "#elseif( ${MailComposer.TokenTypeCtkip} )"
The lines to be added in notepad:
#elseif( (${MailComposer.TokenTypeCtkip}) && (${MailComposer.TokenType} == "SecurID(R) Authenticator for Windows 6.x"))
2. Use this link to import your token:${MailComposer.NL}${MailComposer.NL}
${MailComposer.CtkipURL}${MailComposer.NL}${MailComposer.NL}
After that copy the content of the notepad and paste it in the Security Console > Setup > Self-service settings > Provisioning > Edit Workflow policy > Software Token > E-mail Notification Templates
4. Click on 'Save & Finish'
Email recieved by the user if the token is distributed using delivery method 'CT-KIP URL' and device type 'Desktop PC 4.x' - Old App
- Email recieved by the user if the token is distributed using delivery method 'CT-KIP URL' and device type 'SecurID Authenticator for Windows 6.x' - New App
Emails sent to users contain the software tokens distribution link using CT-KIP URL and Device Type SecurID Authenticator for Windows 6.x contains NO activation codes.
Attachments
If the attachment does not open when clicked, please refresh the page and try again. You must be logged into view the file(s).
Related Articles
CT302 IHS redirecting to port 80 not 443 2Number of Views Error scheduling data purging after new installation of RSA Identity Governance & Lifecycle 7.1.0 GA 181Number of Views Agent 7.X for IIS 7.5 on Windows 2008 for SecurID: AUTHN_METHOD_FAILED when trying to authenticate 196Number of Views How to automatically distribute a soft token to Android with AMBA via CT-KIP 507Number of Views In RSA Identity Governance & Lifecycle 7.0.1, Review Reminder email sent out before configured period has elapsed 10Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?