I unassigned a token from the user then removed them from AD group. Ran a clean up and it removed the user. Now my token statistics show 1 short of what I should have. Does it take a certain amount of time to show it as unassigned?
No, that token should be available as soon as you un-assign it.
In fact, Clean-up jobs are a way to automate un-assigning tokens, so if you manually un-assigned a particular Token SN, you won't find that user/SN combination in the Clean up list.
Or many sites skip the manual un-assign and remove or move out of scope AD /LDAP users, which a clean-up job is designed to find and un-assign tokens for you.
Do you know the Serial Number, you could search for it. It is possible to delete tokens from the Security console.
Jay Guillette provided great information. If you reply, please do not post your token serial numbers on RSA Link.
See Tips for Posting Questions to the RSA SecurID Access Community for more information.
If it is truly missing just reimport the original seed record and do not overwrite duplicates.
Or, restore a backup (made when the token existed) to a lab or dev primary,
and use export/import tokens to move a copy of the token from dev to prod.
Retrieving data ...