Skip to main content

September 22, 2025 Archived

Configure RSA SecurID Authentication in Omnissa Access

After the Omnissa Access connector is configured as the authentication agent in the RSA Authentication Manager server, you set up RSA SecurID in the Omnissa Access console.

Note: This information applies to Omnissa Access connector 21.08 and later. If you are using an earlier version of the connector, see earlier versions of the Managing User Authentication Methods in Omnissa Access guide.

Prerequisites

  • Verify that RSA Authentication Manager (the RSA SecurID server) is installed and properly configured.
  • If you have deployed multiple RSA Authentication Manager server instances, you must configure them behind a load balancer. Make sure that you meet the requirements listed in Omnissa Access Requirements for RSA SecurID Load Balancer.
  • Make sure that all User Auth service instances in your environment are Omnissa Access Connector version 21.08. You cannot configure User Auth authentication methods if you mix connector versions 21.08 and 20.x.
  • If a proxy server is configured with the User Auth service, the communication port that is configured for the RSA Authentication Manager server must be open on the proxy server.

Procedure

  1. In the Omnissa Access console Integrations > Connector Authentication Methods page, click NEW and select RSA SecurID (cloud deployment).

  2. In the Directory and Hosts screen, select the directory and the service hosts to configure with this authentication method.

  3. In the Configuration page, configure the RSA SecurID authentication method settings.

    Information from the RSA Authentication Manager server is required when you configure the page.

    OptionAction
    Number of authentication attempts allowedEnter the maximum number of failed login attempts when using the RSA SecurID token. The default is five attempts.
    Note: When more than one directory is configured and you implement RSA SecurID authentication with additional directories, configure Number of authentication attempts allowed with the same value for each RSA SecurID configuration. If the value is not the same, SecurID authentication fails.
    SecurID Server HostnameEnter the RSA Authentication Manager server host name, for example, myserver.example.com. If you have configured multiple instances of the RSA Authentication Manager server behind a load balancer, enter the load balancer host name instead. For example, lb.example.com.
    SecurID Server Communication PortEnter the communication port of the RSA Authentication Manager instance. The default port is 5555. To get the communication port number, log in to the RSA Security Console, navigate to the Setup > System Settings > RSA SecurID Authentication API page, and copy the Communication Port number.
    SecurID Server Access KeyEnter the Access Key from the RSA Authentication Manager instance. To get the access key, in the RSA Security Console, navigate to the Setup > System Settings > RSA SecurID Authentication API page, and copy the Access Key listed under Agent Credentials.
    SecurID Server CA/SSL certificateIf the RSA Authentication Manager server or the load balancer server has a self-signed certificate, copy and paste the certificate into the text box. If the server has a certificate signed by a public Certificate Authority, uploading a certificate is not required.
    Authentication Attempt timeout in secondsEnter the number of seconds for which the authentication attempt should be available. The authentication attempt times out after that. The default value is 180 seconds.
  4. Click NEXT to review the configuration and then click SAVE.

What to do next

Add the RSA SecurID authentication method to the built-in identity provider.

Add the authentication method to the default access policy. In the console, go to the Resources > Policies page and edit the default policy rules to add the SecurID authentication method to the rule. See Managing Access Policies in the Omnissa Access Service.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…