This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

RSA Link website migration to new platform is in progress

View Status

RSA SecurID® Access Cloud Authentication Service Documentation

Browse the official RSA SecurID Access Cloud Authentication Service documentation for helpful tutorials, step-by-step instructions, and other valuable resources.
  • RSA Link
  • :
  • Products
  • :
  • RSA SecurID Suite
  • :
  • RSA SecurID Access
  • :
  • Cloud Authentication Service
  • :
  • Documentation
  • :
  • Authenticator Registration
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
Versions
Collections
All Downloads

Table of Contents

  •   RSA SecurID Access Product Overview
    •   RSA SecurID Access Overview
  •   Administrators
    •   Administrative Roles for the Cloud Administration Console
  •   Company Settings
    •   Configure Company Information and Certificates
  •   Identity Routers
    •   Planning Your Identity Router Deployment
      •   Identity Routers
  •   Identity Sources
    •   Identity Sources for the Cloud Authentication Service
  •   Assurance Levels
    •   Assurance Levels
  •   Access Policies
    •   Planning Resource Protection with Multifactor Authentication
  •   Clusters
    •   Clusters
  •   High Availability
    •   Relying Parties
  •   and Backups
    •   RADIUS for the Cloud Authentication Service Overview
  •   Relying Parties
    •   Cloud Authentication Service Certificates
  •   RADIUS
    •   Integrated Windows Authentication
  •   Certificates
    •   Adding Identity Providers
  •   Integrated Windows Authentication
    •   Manage the Application Catalog
  •   Identity Providers
    •   User Application Portal
  •   Web Applications
    •   Authentication Methods for Cloud Authentication Service Users
  •   User Application Portal
    •   Cloud Authentication Service User System Requirements
  •   Authentication Methods and Emergency Access
    •   Cloud Authentication Service Rollout to Users
  •   Users and Authenticators
  •   End User Rollout
    •   Using the Cloud Administration APIs
  •   RSA Authentication Manager Integration
    •   Manage the RSA SecurID Authentication API Keys
  •   Cloud Administration APIs
    •   Logging for the Cloud Authentication Service
  •   RSA SecurID Authentication API
    •   Troubleshooting Cloud Authentication Service User Issues
  •   Logging
    •   Product Documentation
  •   Troubleshooting
    •   Copyright

Product Resources

  •   Advisories
    •   Product Advisories
    •   Security Advisories
    •   Service Notifications
    •   Technical Advisories
  •   Blog
  •   Discussions
  •   Documentation
    •   Authentication Agents
      •   API / SDK
      •   Apache Web Server
      •   Citrix StoreFront
      •   IIS Web Server
      •   Microsoft AD FS
      •   Microsoft Windows
      •   PAM
    •   Authentication Client
    •   Authentication Engine
    •   Authentication Manager
    •   Cloud Authentication Service
    •   Hardware Tokens
    •   MFA Agents
      •   macOS
      •   Microsoft Windows
    •   Software Tokens
      •   Android
      •   Blackberry
      •   Blackberry 10
      •   iOS
      •   macOS
      •   Token Converter
      •   Windows
      •   Windows Phone
  •   Downloads
    •   Authentication Agents
      •   API / SDK
      •   Apache Web Server
      •   Citrix StoreFront
      •   IIS Web Server
      •   Microsoft AD FS
      •   Microsoft Windows
      •   PAM
    •   Authentication Client
    •   Authentication Engine
    •   Authentication Manager
    •   Cloud Authentication Service
    •   MFA Agents
      •   macOS
      •   Microsoft Windows
    •   Software Tokens
      •   Android
      •   Blackberry
      •   Blackberry 10
      •   iOS
      •   macOS
      •   Token Converter
      •   Windows
      •   Windows Phone
  •   Events
  •   Ideas
  •   Integrations
  •   Knowledge Base
  •   RSA SecurID Access Prime
  •   Training
  •   Videos

Users complete RSA SecurID Authenticate device registration so that they can use the RSA SecurID Authenticate app (registered on a phone, tablet, or desktop or PC) to authenticate to protected applications.

Users complete authenticator registration so that they can use the RSA SecurID Authenticate app (registered on a phone, tablet, or desktop or PC) or FIDO authenticator to authenticate to protected applications.

Registration binds the authenticator to the user. After registration, when the user needs to authenticate to an application, RSA SecurID Access prompts the user for methods that the user can complete, for example, Approve, RSA SecurID Authenticate Tokencode, or Device Biometrics. Users who do not register a device using the RSA SecurID Authenticate app are not presented with authentication methods that require the app.

SMS Tokencode, Voice Tokencode, and RSA SecurID token do not require this type of registration.

A user can register two authenticators:

  • A single device with the RSA SecurID Authenticate app installed

  • A FIDO authenticator

For more information, see:

  • Registration for iOS, Android, and Windows Devices

  • Registration and User or Authenticator Changes for iOS, Android, and Windows Devices

  • Registration with Multiple Accounts for iOS, Android, and Windows Devices

  • Registration for FIDO Authenticators

  • Registration and User or Authenticator Changes for FIDO Authenticators

​Registration for iOS, Android, and Windows Devices

Users can register an iOS, Android, or Windows device using one of the following methods.

Registration MethodDescription
Use RSA SecurID Access My Page.

My Page is web portal that helps provide a secure way for users to register iOS, Android, or Windows devices using multifactor authentication and QR or numeric registration codes. Users sign into My Page on one device (for example, a computer), download the RSA SecurID Authenticate app on another device (iOS or Android), scan a QR code, and complete an optional test authentication. Users can also manually enter a numeric Registration Code if they are unable to scan a QR code.

By default, My Page is disabled. When you enable it, you can also select an access policy that determines which users are allowed to use My Page and which authentication requirements they must satisfy to access the page. For more information, see Manage My Page

User enters an LDAP password as the Registration Code into the RSA SecurID Authenticate app.

The user downloads the RSA SecurID Authenticate app on a device (iOS, Android, or Windows 10) and enters the identity source email address, your Company ID, and the identity source password (as the Registration Code) in the app.

You can use the Device Registration Using Password policy to restrict which users are allowed to complete device registration using this method. For more information, see Device Registration Using Password Policy.

User enters a Registration Code generated by the administrator.You use the Cloud Administration Console to generate a numeric Registration Code and then securely provide it to the user. The user downloads the RSA SecurID Authenticate app on a device (iOS, Android, or Windows 10) and enters the user identity source email address, your Company ID, and the Registration Code in the app. For more information, see Manage Users for the Cloud Authentication Service - Generate a Device Registration Code.

For a complete overview of the steps users perform to complete registration, see Registering Devices with RSA SecurID Authenticate App. For rollout information, see Cloud Authentication Service Rollout to Users.

​Registration and User or Authenticator Changes for iOS, Android, and Windows Devices

The following table summarizes how RSA SecurID Access handles registration with user or changes for iOS, Android, and Windows devices.

Situation How RSA SecurID Access Handles It
A user completes registration, deletes or uninstalls the RSA SecurID Authenticate app, and then later needs to complete registration again on the same device. The user installs the RSA SecurID Authenticate app again and re-registers the device without administrative action.
  • A user completes registration on one device and then gets a new device. The user needs to complete registration on the new device.

  • A user performs a factory reset on a registered device and wants to reinstall the app on the same device.

The user can delete the current device in My Page , and then complete registration. Or the administrator must delete the user's current device before the user can complete device registration again.

  • An existing user who has completed device registration on the device no longer needs the device and gives the device to a new user.

  • An existing user who has completed device registration on the device no longer needs the device, performs a factory reset, and gives the device to a new user.

  1. If necessary, the existing user deletes the device in My Page or deletes the company in the app.

  2. The new user installs the app and completes device registration without administrative action.

​Registration with Multiple Accounts for iOS, Android, and Windows Devices

An individual user can use the RSA SecurID Authenticate app on a single registered device to authenticate to resources protected by up to 10 different accounts.

For example, a user who is a contractor for both Company A and Company B can use a single device to perform step-up authentication to access both companies. The user registers the device for one company and uses the My Accounts ngx_g_ic_account_circle_blue.png screen to add additional accounts as needed.

An administrator might use a single device for testing the behavior of the RSA SecurID Authenticate app for a company's testing environment and production environment. If each environment has a unique company ID, the administrator adds an account for each company. Or if each environment uses the same company ID but has a unique user ID, the administrator adds an account for each user ID.

If an administrator for one account uses the Cloud Administration Console to delete a user's registered device, the RSA SecurID Authenticate app on the user's device continues to work normally for any other account. The activity from one account does not affect the app behavior for other accounts.

​Registration for FIDO Authenticators

RSA SecurID Access supports the following FIDO authenticators:

  • Security keys. Roaming (or hardware) USB, BLE, or NFC keys that are FIDO2 or U2F compliant.

  • Windows Hello

    See Windows Hello and FIDO2 Security Keys enable secure and easy authentication for shared devices.

  • Android phone

    See Now generally available: Android phone’s built-in security key.

For FIDO authenticators, registration happens in one of two ways:

  • The first-time user clicks an icon for a protected application, enters an identity source password, connects the FIDO authenticator, and, if required, taps the authenticator. Subsequent authentications do not require a password. This is the default registration method and is only available for security keys.

  • The user goes to My Page to register the FIDO authenticator. Users authenticate to My Page according to the access policy protecting My Page. You can make My Page registration a requirement by enabling both My Page and FIDO authenticator registration in the Cloud Administration Console at Platform > My Page. After both functions are enabled, users can no longer register FIDO authenticators during first-time authentication.

For a list of supported authenticators and environments, see Cloud Authentication Service User System Requirements.

​Registration and User or Authenticator Changes for FIDO Authenticators

The following table summarizes how RSA SecurID Access handles registration with user or authenticator changes for FIDO authenticators.

SituationHow RSA SecurID Access Handles It
A user registers a FIDO authenticator and then loses the authenticator.The administrator deletes the user's lost authenticator from the Cloud Authentication Service, or the user deletes it using My Page. The administrator gives the user a new authenticator to register.
A user registers a FIDO authenticator, no longer needs it, and gives it to another user.The administrator deletes the user's authenticator or the user deletes it using My Page. The new user must re-register the authenticator.

 

 

 

Previous Topic:Cloud Authentication Service User System Requirements
Next Topic:RSA SecurID Authenticate App Security Features
You are here
Table of Contents > Users and Authenticators > Authenticator Registration
Labels (1)
Labels:
  • Administration

Tags (19)
  • Admin
  • Administration
  • Administrative
  • browser device
  • CAS
  • Cloud
  • Cloud Auth Service
  • Cloud Authentication
  • Cloud Authentication Service
  • device registration
  • Docs
  • Documentation
  • how do i register a device
  • Mobile Device
  • Product Docs
  • Product Documentation
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
0 Likes
Was this article helpful? Yes No
Share
No ratings

On this page

Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.