User Event Monitor Messages for Cloud Access Service (400 - 1409)
a month ago

User Event Monitor Messages for Cloud Access Service (400 - 1409)

User events trigger the following messages to appear in the User Event Monitor. New user events have been added and descriptions for some of the events have been modified recently. If these descriptions are used for SIEM integrations, they must be modified accordingly.

Event Code Level Category Description
400noticeAuthenticationUser re-enabled in the Cloud Authentication Service.
401noticeAuthenticationUser disabled in directory server now disabled in the Cloud Authentication Service.
402noticeAuthenticationUser not found in directory server now disabled in the Cloud Authentication Service.
403errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Invalid email.
404errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Duplicate email.
405errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Disabled in directory server.
406errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Missing unique identifiers in directory server.
407errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Unknown reason.
408errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Missing email.
409errorAuthentication

Just-in-time synchronization failed to synchronize user with the Cloud Authentication Service - No identity router can service this request.

410errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - Unable to contact directory server.
413errorAuthenticationJust-in-time synchronization failed to synchronize user with the Cloud Authentication Service - LDAP search of the directory server failed.
500noticeAuthenticationCloud Identity Provider (IDP) authentication succeeded.
501errorAuthenticationCloud Identity Provider (IDP) authentication failed.
600noticeAuthenticationSecurID OTP Credential enrollment failed - User name not found for user.
601 notice Authentication

Authentication Manager successfully authenticated SecurID OTP Credential.

602 notice Authentication

Authentication Manager successfully authenticated SecurID OTP Credential - New PIN accepted.

603 notice Authentication

Authentication Manager unable to authenticate SecurID OTP Credential – New PIN required.

604 notice Authentication

Authentication Manager requires next OTP for SecurID OTP Credential.

605 error Authentication

Authentication Manager unable to authenticate SecurID OTP Credential - Invalid OTP.

606 error Authentication

Authentication Manager unable to authenticate SecurID OTP Credential - Invalid next OTP.

607 error Authentication

Authentication Manager unable to authenticate SecurID OTP Credential - Invalid PIN.

608 error Authentication

Unable to authenticate SecurID OTP Credential – Authentication Manager service unavailable.

609 error Authentication

Authentication Manager unable to authenticate SecurID OTP Credential - Unknown cause.

610error Authentication SecurID OTP Credential enrollment succeeded.
611errorAuthentication

Authentication Manager unable to authenticate SecurID OTP Credential - Request timed out.

650noticeAuthenticationCloud Authentication Service unable to validate credentials. Request redirected to Authentication Manager.
652noticeAuthenticationCloud Authentication Service successfully validated Hardware Authenticator credentials.
653errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator – Invalid credentials.
654errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator - Authenticator not found.
655errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator – Invalid serial number.
656errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator - Authenticator PIN not set.
657errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator – Authenticator expired.
658errorAuthentication Cloud Authentication Service unable to test Hardware Authenticator – Authenticator disabled.
659errorAuthenticationCloud Authentication Service unable to test Hardware Authenticator – User not authorized to use this authenticator.
660noticeAuthenticationCloud Authentication Service successfully validated Hardware Authenticator credentials.
661noticeAuthenticationHardware Authenticator locked in Cloud Authentication Service. Request redirected to RSA Authentication Manager.
662errorAuthenticationHardware Authenticator locked in Cloud Authentication Service - User exceeded maximum failed attempts.
663errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Invalid PIN and/or OTP.
664errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Previously used OTP was reused for authentication.
665errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Authenticator PIN not set.
666errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Authenticator expired.
667errorAuthentication Hardware Authenticator authentication to Cloud Authentication Service failed - Authenticator disabled.
670errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Invalid PIN.
671errorAuthenticationHardware Authenticator authentication to Cloud Authentication Service failed - Authenticator credentials cannot be verified.
680noticeAuthenticationOTP Credential registration succeeded for RSA DS100 Hardware Authenticator.
681errorAuthenticationOTP Credential registration failed for RSA DS100 Hardware Authenticator.
682errorAuthenticationOTP Credential registration failed for RSA DS100 Hardware Authenticator - User not authorized to use this token.
701 notice Authentication Approve authentication succeeded.
702 error Authentication Approve authentication failed - User response timed out.
703 error Authentication Approve authentication failed - User denied approval.
704 error Authentication Approve enrollment failed.
707 notice Authentication Approve enrollment succeeded.

709

error

Authentication

Approve authentication failed - All in-progress authentication requests canceled.

713notice Authentication

Agent does not support the Code Matching feature. Code will not be used as part of the Approve push notification.

714 notice Authentication Agent does not support the Code Matching feature. Code will not be used as part of the Biometric push notification.
715 notice Authentication Authenticator does not support the Code Matching feature. Code will not be used as part of the Biometric push notification.
716noticeAuthenticationAuthenticator does not support the Code Matching feature. Code will not be used as part of the Approve push notification.
720errorAuthenticationApprove authentication failed - Disabled device platform
801 notice Authentication

Biometric authentication succeeded.

802 error Authentication

Biometric authentication failed - User response timed out.

803 error Authentication

Biometric authentication failed - User denied access to biometric credentials.

804 error Authentication

Biometric authenticator enrollment failed.

805 error Authentication

Biometric authentication failed - Unexpected error.

806 notice Authentication

Biometric authenticator enrollment succeeded.

807 notice Authentication

Biometric authenticator unenrollment succeeded.

808errorAuthenticationBiometric authentication failed - All in-progress authentication requests canceled.
809errorAuthenticationBiometric authentication failed - Authenticator not found.
810errorAuthenticationBiometric authentication canceled.
811noticeAuthenticationBiometric authenticator unenrollment failed.
812errorAuthenticationBiometric authentication failed - Disabled device platform.
831noticeAuthenticationDevice Biometrics (RSA Agent) authentication succeeded.
832errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - User response timed out.
833 errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - User denied access to biometric credentials.
834 errorAuthenticationDevice Biometrics (RSA Agent) authenticator enrollment failed.
835errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - Unexpected error.
836 noticeAuthenticationDevice Biometrics (RSA Agent) authenticator enrollment succeeded.
837 errorAuthenticationDevice Biometrics (RSA Agent) authenticator unenrollment succeeded.
838 errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - All in-progress authentication requests cancelled.
839 errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - Authenticator not found.
840 notice AuthenticationDevice Biometrics (RSA Agent) authentication cancelled.
841 errorAuthenticationDevice Biometrics (RSA Agent) authenticator unenrollment failed.
842errorAuthenticationDevice Biometrics (RSA Agent) authentication failed - Disabled device platform.
901 notice Authentication Portal sign-in succeeded.
902 error Authentication Portal sign-in failed - Authentication failed.
903 error Authentication Portal sign-in failed - Credentials are associated with multiple user accounts.
904 error Authentication Portal sign-in failed - Internal server error.
905 error Authentication Portal sign-in failed - Concurrent session limit reached.
906 error Authentication Portal sign-in failed - Password reset required.
907 notice Authentication Portal sign-out succeeded.
908 notice Authentication Protected application authentication attempt made.
909 notice Authentication Protected application authentication succeeded.
910 error Authentication Protected application authentication failed.
911 notice Authentication Additional authentication initiated.
912 notice Authentication Additional authentication succeeded.
913 error Authentication Additional authentication failed.
931noticeAuthenticationAdditional authentication is not needed because the user already authenticated at the same assurance level or higher.
932 error Authentication Additional authentication failed - User account disabled.
933errorAuthenticationPassword authentication succeeded - Client does not support required additional authentication methods - Access denied.
934noticeAuthenticationPassword authentication succeeded.
935errorAuthenticationUnsuccessful password authentication – Access denied.
936errorAuthenticationUnsuccessful password authentication - Credentials are associated with multiple user accounts.
937errorAuthenticationUnsuccessful password authentication - Internal server error.
938errorAuthenticationUnsuccessful password authentication - Concurrent session limit reached.
939noticeAuthorizationPassword authentication succeeded - Policy does not require additional authentication - Access granted.
940errorAuthorizationPassword authentication succeeded - User prohibited by policy settings - Access denied.
941errorAuthorizationPassword authentication succeeded - Access prohibited by conditional policy settings - Access denied.
942noticeAuthenticationPortal sign-out - User automatically signed out because of session timeout.
943noticeAuthenticationPortal sign-out - User session removed. This might occur if the user has too many sessions.
944noticeAuthenticationPortal sign-out - No user session. For example, the session timed out and was removed.
945noticeAuthenticationProtected HFED application authentication succeeded through My Page.
1409errorAuthenticationMobile Passkey (RSA Agent) authentication failed - Disabled device platform.

 

See:

User Event Monitor Messages for Cloud Access Service (02 - 345)

User Event Monitor Messages for Cloud Access Service (1501 - 20406)

User Event Monitor Messages for Cloud Access Service (20601 - 38000)