Unclear Error Message Possible for Application Protected by Fingerprint Only
2 years ago
Originally Published: 2015-06-09
Article Number
000062818
Applies To
RSA Via Access 1.0
Issue
If application access policy requires Fingerprint authentication but the user does not have an IOS device registered with this capability the authentication will fail with an "Unsuccessful authentication, try again" message.

User-added image

No indication of the actual failure reason is provided.
Cause
If the step-up scheme "Basic Step-Up Authentication" with High Sensitivity is chosen as part an access policy the step-up authentication will require Fingerprint.
Resolution
An improved error message is planned for a future release.
Workaround
Unless all users have registered iPhones that support Apple Touch ID RSA recommends not using "Basic Step-Up Authentication" with High Sensitivity.  Either use a different pre-configured scheme or create a custom scheme where Fingerprint OR another authentication method is required.