Troubleshooting: Helpdesk or Self Service Realm Does Not Show a User's Mobile or OTP Devices

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 21.04 and later
     
     

    Overview

    The Helpdesk realm or Self Service realm does not show a user's mobile or one-time passcode (OTP) devices when looking up that user, even though the user has enrolled devices.

    There are two unrelated causes, so a fix for one cause will not resolve the other:

    • See Cause 1 - The realm cannot connect to the Mobile Service because the wrong client certificate is selected
    • See Cause 2 - The realm's Mobile Tokens display setting is not set to show devices

    Helpdesk or Self Service device management page showing the Mobile Devices section boxed in red and reading "No registered mobile devices," despite the user having other enrolled MFA methods.


     

    In this article


     

    Cause 1: Incorrect Client Certificate Selected

    The realm cannot connect to the Mobile Service because the correct client certificate is not selected on the System Info tab. Audit logs show an authorization failure similar to:

    Message="[ReportIp].[ReportAsync] Exception Error while retrieving or refreshing Titan access_token. Cloud Response: Unauthorized-{"error":"invalid_client","errorMessage":"Client authentication failed (e.g., unknown client, no client authentication included, or unsupported authentication method). not_found"}

     

    Resolution 1:

    To resolve this:

    1. Open the Admin Console and navigate to the System Info tab of the affected realm.
    2. Check the Client Cert Serial Nbr field. Make sure it is set to the SecureAuth Appliance Cert.
    3. Save the settings.

    System Info tab with the Client Cert Serial Nbr field boxed in red, showing the certificate serial number that must match the SecureAuth Appliance Cert.



     

    Cause 2: Mobile Tokens Display Setting Not Enabled

    Starting in 21.04, Mobile Service introduced a separate display setting for whether Mobile Devices appear on the Helpdesk or Self Service page. This setting defaults in a way that can leave Mobile Devices hidden even though the user has devices enrolled.

     

    Resolution 2:

    To resolve this:

    1. Open the Admin Console and navigate to the Post Authentication tab of the affected realm.
    2. Click the Configure Self Service Page link (or the Helpdesk equivalent, if configuring a Helpdesk realm).
    3. Set Mobile Tokens to Show Enabled.
    4. Save the settings, then log in again.

    Mobile Tokens dropdown on the Configure Self Service Page settings, with the options Hide, Show Enabled, and Show Disabled, and Show Enabled selected.

    The user's mobile and OTP devices now appear on the Helpdesk or Self Service page:

    Helpdesk or Self Service device management page now listing several enrolled Mobile Devices along with a SecureAuth OTP Mobile App entry and an OTP App entry.

     
     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.