Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
JuliusSekiteri
Employee
Employee

Challenge on Unsupported offline Authentication for MFA.

Jump to solution

Hello All, I have been reading many post on the MFA Token, I have configured it and I have had the fill of it but I have a challenge, which is non support for offline authentication for windows login. What happened to employee on vacation using MFA tokens or when there is issues with the network? How would they authenticate? Will like to know if RSA has plan resolving this?

Labels (1)
0 Likes
1 Solution

Accepted Solutions
LyndalK
Frequent Contributor Frequent Contributor
Frequent Contributor

RSA SecurID tokens with RSA Authentication Manager support offline authentication.  For more information, see the Offline Authentication Policy page in the RSA Authentication Manager online help.  The offline authentication feature, if configured, allows users to authenticate with their tokens when their computers are not connected to the network.  You can optionally allow Authentication Manager to automatically provide the user's Windows Login Password with a successful SecurID authentication.  Offline authentication security is explained in detail in the KB article 000025725 - Questions on the security of offline authentication data in the RSA SecurID Authentication Agent for Microsoft Windows.

I see your post has been tagged for the RSA Cloud Authentication Service .  However, that service does not directly support offline authentication, because it is typically used to protect applications which must be accessed across the network - not for Windows login - so allowing authentication offline would not make sense.  In addition, the Cloud Authentication Service does not require Agents to be installed in applications, so there is no Agent to store a set of downloaded token codes.

However, if you have a specific business application in mind where you think offline authentication would be useful for the RSA Cloud Authentication Service, such as when you have enabled Cloud Authentication Service users to access resources protected by RSA SecurID, we recommend posting that as a suggestion on the RSA Ideas for the RSA SecurID® Suite page.

View solution in original post

1 Reply
LyndalK
Frequent Contributor Frequent Contributor
Frequent Contributor

RSA SecurID tokens with RSA Authentication Manager support offline authentication.  For more information, see the Offline Authentication Policy page in the RSA Authentication Manager online help.  The offline authentication feature, if configured, allows users to authenticate with their tokens when their computers are not connected to the network.  You can optionally allow Authentication Manager to automatically provide the user's Windows Login Password with a successful SecurID authentication.  Offline authentication security is explained in detail in the KB article 000025725 - Questions on the security of offline authentication data in the RSA SecurID Authentication Agent for Microsoft Windows.

I see your post has been tagged for the RSA Cloud Authentication Service .  However, that service does not directly support offline authentication, because it is typically used to protect applications which must be accessed across the network - not for Windows login - so allowing authentication offline would not make sense.  In addition, the Cloud Authentication Service does not require Agents to be installed in applications, so there is no Agent to store a set of downloaded token codes.

However, if you have a specific business application in mind where you think offline authentication would be useful for the RSA Cloud Authentication Service, such as when you have enabled Cloud Authentication Service users to access resources protected by RSA SecurID, we recommend posting that as a suggestion on the RSA Ideas for the RSA SecurID® Suite page.