User Event Monitor Messages for Cloud Access Service (20601 - 38000)
a month ago

User Event Monitor Messages for Cloud Access Service (20601 - 38000)

User events trigger the following messages to appear in the User Event Monitor. New user events have been added and descriptions for some of the events have been modified recently. If these descriptions are used for SIEM integrations, they must be modified accordingly.

Event Code Level Category Description
20601errorAuthenticationRADIUS - LDAP authentication succeeded - Access denied. Policy does not contain RADIUS-compatible methods for additional authentication.
20602errorAuthenticationRADIUS - LDAP authentication succeeded - Access denied. No authenticators were found for additional authentication methods.
20603errorAuthenticationRADIUS - Invalid format for additional authentication request - Access denied.
20604errorAuthenticationRADIUS - Invalid checklist attributes - Access denied.
20605errorAuthenticationRADIUS - the Cloud Authentication Service unreachable - Access denied.
20606errorAuthenticationRADIUS – Approve authentication failed – Method timeout.
20608errorAuthentication

RADIUS - Biometric authentication failed - Method timeout.

20609errorAuthenticationRADIUS - Authentication failed - Internal error.
20610errorAuthenticationRADIUS - Approve authentication failed - Authentication could not be completed within push notification timeout.
20611errorAuthenticationRADIUS - Biometric authentication failed - Authentication could not be completed within push notification timeout.
20612noticeAuthenticationUser initiated additional authentication, primary authentication managed by RADIUS client.
20613noticeAuthenticationRADIUS – User selected last used method or default assurance level method for additional authentication.
20614noticeAuthenticationRADIUS - User selected SecurID OTP or Authenticate OTP for additional authentication.
20616errorAuthenticationRADIUS - Authentication denied as user exceeded attempt threshold.
20701errorAuthenticationAccess denied – User not a member of any identity source in access policy.
20702errorAuthenticationAccess denied – User does not match any rule sets or matches a deny rule set in access policy.
20703errorAuthenticationAccess denied – Policy authentication conditions deny access.
20704noticeAuthenticationAccess allowed – Policy conditions allow access without additional authentication.
20801errorAuthenticationSMS OTP message transmission attempted.
20802errorAuthenticationSMS OTP message transmission attempt failed - Invalid phone number.
20803errorAuthenticationSMS OTP message transmission attempt failed.
20804noticeAuthenticationSMS OTP regenerated.
20805errorAuthenticationSMS OTP delivery failed.
20851noticeAuthenticationVoice OTP call succeeded.
20852errorAuthenticationVoice OTP call attempt failed - Invalid phone number.
20853errorAuthenticationVoice OTP call attempt failed.
20854noticeAuthenticationVoice OTP regenerated.
20855errorAuthenticationVoice OTP delivery failed.

20900

notice

Authentication

OIDC - Authentication request received.

20901

notice

Authentication

OIDC - ID Token sent for successful user authentication.

20902

error

Authentication

OIDC - Response sent for unsuccessful user authentication.

20903

error

Authentication

OIDC - Error response sent.

20909noticeAuthenticationOIDC - Successful user authentication through SSO.
20910noticeAuthenticationOIDC - Successful user authentication through Relying Party.
20912noticeAuthenticationOIDC - Successful user authentication through AAD Relying Party.
21901noticeAuthenticationSMS OTP verification succeeded.
21902errorAuthenticationSMS OTP verification failed
21903errorAuthenticationSMS OTP authentication method locked - User exceeded maximum OTPs allowed.
21904errorAuthenticationSMS OTP verification failed – internal error.
21951noticeAuthenticationVoice OTP verification succeeded.
21952errorAuthenticationVoice OTP verification failed.
21953errorAuthenticationVoice OTP authentication method locked - User exceeded maximum OTPs allowed.
21954errorAuthenticationVoice OTP verification failed – internal error.
23000errorAuthenticationApprove with authenticator unlock enabled – No push notification sent for Approve. RSA SecurID Authenticator version not supported.
24001noticeAuthenticationMy Authenticators sign-in succeeded.
24002noticeAuthenticationMy Page sign-out succeeded.
24003noticeAuthenticationMy Page session expired.
24004noticeAuthenticationUser deleted authenticator in My Page.
24005noticeAuthenticationUser deleted FIDO authenticator in My Page.
24006noticeAuthenticationHardware Authenticator registration successful.
24007noticeAuthenticationHardware Authenticator registration unsuccessful.
24008noticeAuthenticationHardware Authenticator unassigned from this user.
24010noticeAuthenticationHardware Authenticator PIN reset successful.
24011errorAuthenticationHardware Authenticator PIN reset unsuccessful.
24012noticeAuthenticationHardware Authenticator successfully resynchronized.
24013errorAuthenticationHardware Authenticator resynchronization unsuccessful.
24014noticeAuthenticationHardware Authenticator test successful.
24015errorAuthenticationHardware Authenticator test unsuccessful.
24016errorAuthenticationAttempt to unassign Hardware Authenticator unsuccessful.
24017noticeAuthenticationHardware Authenticator registration successful.
24018noticeAuthenticationHardware Authenticator rename successful.
24019errorAuthenticationHardware Authenticator rename unsuccessful.
24020noticeAuthenticationUser deleted OTP credential for RSA DS100 Hardware Authenticator from My Page.
24021noticeAuthenticationApplication credential reset successful in My Applications portal.
24022noticeAuthenticationUser accessed My Authenticators successfully.
24023noticeAuthenticationMy Authenticators authentication succeeded.
24024errorAuthenticationMy Authenticators authentication failed.
24025noticeAuthenticationMy Applications sign-in succeeded.
24026errorAuthenticationError retrieving Hardware Authenticator by Serial Number.
24027noticeAuthenticationHardware Authenticator retrieved successfully.
25001noticeAuthenticationEvaluated identity confidence. See Condition Attributes for Access Policies - Reporting a User's Identity Confidence Score for details.
25002noticeAuthenticationFailed to evaluate identity confidence.
25003noticeAuthenticationIdentity confidence collection disabled. Evaluation skipped, returning low identity confidence.
26000noticeAuthenticationEmergency Access Code verification succeeded.
26001errorAuthenticationEmergency Access Code verification failed.
26002errorAuthenticationEmergency Access Code not configured.
26003errorAuthenticationEmergency Access Code is expired.
26004errorAuthenticationEmergency Access Code locked - User previously exceeded maximum attempts.
26005errorAuthenticationEmergency Access Code now locked.
26007errorAuthentication

Emergency Access Code deactivated as it is marked for one-time use. User already authenticated using this code.

33000noticeApplication InvocationSAML SP application invoked through My Page.
33001noticeApplication InvocationSAML IDP application invoked through My Page.
33002noticeApplication InvocationOIDC application invoked through My Page.
33003noticeApplication InvocationHFED application invoked through My Page.
33004noticeApplication InvocationBookmark application invoked through My Page.
33005noticeApplication InvocationTrusted Header application invoked through My Page.
33006noticeApplication InvocationNTLM application invoked through My Page.
34000error Email CodeInvalid e-mail address.
34001errorEmail CodeE-mail code not sent.
34002noticeEmail CodeE-mail code sent to user.
34003errorEmail CodeE-mail codes don't match.
34004noticeEmail CodeSuccessful e-mail code verification.
34005errorEmail CodeE-mail address not found.
34006errorEmail CodeE-mail code verification failed - E-mail code locked.
34007errorEmail DomainBlocked invalid e-mail domain.
34100errorVerificationVerification was unsuccessful because already enrolled authenticators were found.
34101error VerificationVerification was unsuccessful because user doesn't have exactly one enrolled authenticator.
34102error VerificationVerification was unsuccessful because user enrolled authenticator failed to delete.
34110notice VerificationSuccessful recovery sign-in.
34120notice VerificationUser reported device as lost.
34121notice VerificationUser reported device as stolen.
34122notice VerificationUser reported device as damaged.
34123notice VerificationUser reported device as unusable (other).
38000noticeAuthenticationUser attempted Live Verification with no session started by admin.

 

See:

User Event Monitor Messages for Cloud Access Service (02 - 345)

User Event Monitor Messages for Cloud Access Service (400 - 1409)

User Event Monitor Messages for Cloud Access Service (1501 - 20406)