Troubleshooting: Login for Windows Deletes the Local OATH Cache

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: Login for Windows 22.12 and earlier
     
     

    Overview

    The local OATH cache on a machine can unexpectedly disappear, preventing the user from logging in offline with Login for Windows.

     

    Cause

    This is expected behavior, not a bug. Login for Windows caches OATH using the id GUID from the factors endpoint to identify the specific enrolled device. If that id changes for a user -- for example, because they enrolled a new device -- Login for Windows deletes the old cache and stores the new one as a security measure. If Mobile Service is unavailable, it falls back to reading OATH from the local data store instead; if that attribute is empty there too, it removes the local OATH cache entirely.

     

    Resolution:

    There's nothing to fix -- this is by design. If a user needs offline login to keep working, make sure their enrolled device's id isn't changing unexpectedly (for example, from re-enrolling), since that's what triggers the cache to be cleared.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.