RSA ID Plus
RSA Cloud Authentication Service
RSA MFA Agent for MacOS 1.4.x and later
This article provides general troubleshooting steps for the RSA MFA Agent for MacOS (the MFA Agent).
- Perform the Basic Troubleshooting steps when an issue arises
- Advanced Troubleshooting can be done to gather additional data about the problem
The documentation references provided in this article are for RSA MFA Agent for MacOS v1.4.2, which is the latest version of that MFA Agent at the time of writing.
Equivalent documents for other supported versions are available on the RSA MFA Agent for macOS Documentation page.
Basic Troubleshooting
- Ensure that you are running a supported version of the RSA MFA Agent for MacOS and any other RSA software.
- Support end dates for RSA MFA Agent versions are in section "Authentication Agents & Related SDK" on the Product Version Life Cycle for RSA ID Plus and RSA SecurID.
- Supported versions of the MFA Agent can be downloaded from RSA ID Plus Downloads (RSA Community login required).
- If you are not running the latest version of the RSA MFA Agent, check if the issue is fixed in a later version. See the "Fixed Issues" section in the Release Notes for the latest version on the RSA MFA Agent for macOS Documentation page.
- Ensure the Mac meets the System Requirements in "Chapter 2: Preparing for Installation" on page 16 of the RSA MFA Agent 1.4.2 for macOS Installation and Administration Guide .
- Check if the behaviour is normal and expected. Review the Known Behavior section on page 16, "Chapter 2: Preparing for Installation" of the RSA MFA Agent 1.4.2 for macOS Installation and Administration Guide
- Refer to section Issues and Resolutions in "Chapter 5: Troubleshooting" on page 54 of the RSA MFA Agent 1.4.2 for macOS Installation and Administration Guide .
- In the Cloud Administration Console, check the User Event Monitor and review all events around the time of the issue.
- Are the affected Mac computers managed by any Apple device management software, e.g. Jamf? If so, check that the device management software has not modified or removed any MFA Agent configurations in MacOS system files, such as system.login.console.
- If the issue persists, contact RSA Support to open a support case if you have not done so already.
Advanced Troubleshooting
The below steps are to collect detailed troubleshooting data about MFA Agent issues. Please follow these steps for at least one computer that is encountering the issue, and send the collected data to RSA Support when a support case is opened, and when requested by RSA Support.
- Enable logging for the MFA Agent. See section Enable Logging in "Chapter 5: Troubleshooting" on pages 58-59 of the RSA MFA Agent 1.4.2 for macOS Installation and Administration Guide . Set Log level to verbose .
- Take note of the previous settings so it can be set back to that later.
- If the user is not receiving push notifications when expected or any other RSA Authenticator app issues are occurring, enable Enhanced Log Connection in the app. See How to capture enhanced RSA Authenticator app logs for troubleshooting purposes .
- Follow the steps required to reproduce the issue. Note the date, time (with time zone) and user id of the attempt.
- Optionally, set MFA Agent logging back to previous settings.
- The Log File Count and Log File Size settings will ensure that verbose logs do not take up too much disk space. There is no performance impact of verbose logging. Therefore, verbose logging can be left enabled for an extended time if needed to capture later examples of the issue.
- Send the following items to RSA Support:
- Date, time (with timezone) and user id when the issue occurred at step 4 above, plus any videos, photos, symptom description and error messages.
- MacOS version
- Selected Logs & Reports from the table below, depending on the nature of the issue. RSA Support will advise which ones to send.
| Logs & Reports | Instructions |
| RSA MFA Agent Logs | All files from the /Library/Application Support/RSA MFA Agent/Logs folder. We recommend compressing the Logs folder into a .zip file or similar to send to RSA. |
| CAS User Event Monitor | In the User Event Monitor, select Include Verbose Logs. Then, take screenshots or "print to PDF" of all events for the user's email address around the time the issue was reproduced at step 3 above. If there are no events displayed for the user, then do not filter by user's email address (this will reveal any "user not recognized" issues). If no events at all were logged around that time, inform Support. |
| RSA Authenticator app | Logs from the user's RSA Authenticator app that was used at step 3. See How to capture enhanced RSA Authenticator app logs for troubleshooting purposes |
| MacOS System Configuration |
Run the following three commands from Command Prompt on the Mac used in step 3 above, and send the output to RSA:
|
Related Articles
PKInstallErrorDomain Code=112 seen when installing RSA MFA Agent for Mac 2.0 .pkg on MacOS 26.0.1 12Number of Views macOS administrator locked out due to RSA MFA Agent for macOS misconfiguration 218Number of Views Deploy the RSA MFA Agent for macOS via Microsoft Intune 22Number of Views RSA MFA Agent 2.0 for macOS Installation and Administration Guide 24Number of Views RSA Announces the Release of RSA MFA Agent 2.0 for macOS 18Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x