Version Affected: All
Overview
When signing in to a workstation with Login for Endpoint, a user is prompted for Multi-Factor Authentication (MFA) even though they are within the bypass interval time set in config.json.
Cause
The bypass interval only applies when a user locks their machine and then unlocks it again. It does not apply to restarting the machine or to Remote Desktop Protocol (RDP) disconnect/reconnect policies — those scenarios always require MFA, regardless of the configured bypass interval.
Resolution
Check login.log for the following message:
Bypass interval won't be validated because we are not on an unlock scenario or the session was invalidated. No special action was taken.
If this message appears, the user was not signing in during a lock/unlock scenario, so being prompted for MFA is expected behavior, not a defect.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.