Secure Mobile Access 12.4 Administration Guide

SMA1000 Clients and AMC Authentication support

The RSA SecurID authentication servers are supported by all the actively supported client like Connect Tunnel(CT) on Windows/Mac/Linux platforms, and Workplace.

Access methods like DeviceVPN, ActiveSync, and Outlook access cannot use RSA AM authentication.

After you have configured the RSA SecurID authentication server, when you log to CT or Workplace you can:

  1. User initiates primary authentication by entering the username and Passcode.

    The client displays the user provided Passcode and pass it to RSA Authentication Manager for validation.

    A SecurID Passcode is the combination of a PIN and token code. Similar to the token code, a Passcode is a one-time password (OTP). It is valid only while it is displayed, and it can be used only once. The SecurID Passcode consists of your PIN followed by the token code and you must enter both. For example, if your PIN is 1234 and the token code is 567891, you enter the Passcode as 1234567891.

  2. RSA Authentication Manager requests the next Passcode in case the user exceeds previous wrong attempts more than set policy count. Thus enforcing to change Passcode. The Passcode can be a combination of Pin+Token or only Token based on how it was configured on RSA Security console to authenticate.

    The client displays to change the user's Passcode and to use new pin generated by the authentication server. The token generates a new Passcode at regular intervals, typically every 60 seconds. You then use the generated Passcode when you log in.

  3. Enter the next Passcode to complete the login.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden