iOS native mail app authentication using the RSA® Authentication Agent for Microsoft AD FS fails because "An Error Occurred"
2 years ago
Originally Published: 2020-07-08
Article Number
000043511
Applies To
RSA Product Set: RSA SecurID / RSA SecurID Access
RSA Product/Service Type: Authentication Agent for ADFS
RSA Version/Condition: 2.0.2 and later
Platform: iOS native mail app
Issue
Users authenticating through Microsoft AD FS, with the RSA Authentication Agent configured, are unable to login to the iOS native mail app. 
The message An Error Occurred.  Cannot authenticate. Contact your administrator is displayed instead of step-up authentication.
An Error Occurred
When running the RSA ADFS Agent in debug, you see the following records logged:

2020-03-24 10:09:30,635 [19] DEBUG AuthnContextValidator - Adding default authentication context
2020-03-24 10:09:30,635 [19] DEBUG AuthSessionAdapter - BeginAuthentication(): Authentication context not added.