Troubleshooting: TOTP Fails to Authenticate After Changing the Realm's Datastore Type

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Users can fail to authenticate with TOTP (Time-based One-Time Password) during Two-Factor Authentication after the realm's datastore type is changed.
     

    Cause

    When a user enrolls for TOTP, the value is looked up against whichever Active Directory attribute the datastore type's Search Attribute pointed to at the time of enrollment -- for example, sAMAccountName. Changing the realm's datastore type afterward can change the default Search Attribute, so the realm can no longer find the user's TOTP value using the new attribute.

    The Data tab's Membership Connection Settings, showing Datastore Type set to Active Directory (sAMAccountName).

     

    Resolution:

    1. Go to the realm's Data tab and open Membership Connection Settings.
    2. In the Search Filter section, set Search Attribute back to whichever attribute was in use when users originally enrolled for TOTP. The searchFilter field itself does not need to change.

    The Search Filter section, with Search Attribute set to samAccountName and searchFilter set to (&(saMAccountName=%v)(objectclass=*)).

    Users should now be able to authenticate with TOTP again.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.