macOS administrator locked out due to RSA MFA Agent for macOS misconfiguration
Originally Published: 2020-06-24
Last Modified: 2023-11-30
Article Number
Applies To
RSA Product/Service Type: MFA Agent for macOS
RSA Version/Condition: 1.x
Issue
Cause
Workaround
- SSH to the macOS machine using an administrator account and edit the agent settings at /Library/Preferences/com.rsa.mfaconfig.plist. Options include setting disableCASforUnknownUser=true or enableCAS=false.
- SSH to the macOS machine using an administrator account and uninstall the RSA MFA Agent for macOS by running the following command:
sudo /Library/Application Support/RSA MFA Agent/UninstallRSAmacOSAgent.sh
- Sync the administrator (using sAMAccountName or equivalent) from your identity source to the Cloud Authentication Service and have the admin user register a mobile device. This will allow the administrator to meet the additional authentication requirement enforced by the RSA MFA Agent for macOS.
Related Articles
How many incorrect password entries are permitted before being locked out of a Luna token? 13Number of Views RSA Announces the Release of RSA MFA Agent 2.0 for macOS 18Number of Views SecurID: Locked out of Agent host; cannot authenticate to RSA Authentication Agent for Microsoft Windows. 51Number of Views Windows agentless account keeps locking out. 16Number of Views RSA MFA Agent 2.0 for macOS Installation and Administration Guide 42Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?