Version Affected: 24.04+ Cloud
Overview
In a Cloud deployment, after an administrator clears a Multi-Factor Authentication (MFA) and/or Password (PW) Throttling entry for an affected end user, the process appears to succeed, but the user remains blocked on their next login attempt. There are two independent causes:
- See Cause 1 - MFA and/or PW Throttling is not enabled on the Account Management Realm itself.
- See Cause 2 - The Account Management Realm is using a Theme that is not based on the SA-IdP Theme.
These causes are not related, so a fix for one cause will not resolve the other cause.
In this article
- Cause 1: Account Management Realm Throttling Not Enabled
- Cause 2: Account Management Realm Uses an Incompatible Theme
Cause 1: Account Management Realm Throttling Not Enabled
Clearing a Throttling entry for an end user only takes effect if MFA and/or PW Throttling is enabled on the Account Management Realm itself, not just on the realm the user originally authenticated to. If Throttling is not enabled there, the clear action has no effect on the underlying throttle state, and the user remains blocked on their next attempt. This is a known defect, tracked as EE-3977, fixed in version 26.1.1.
Resolution 1:
To resolve this:
- Open the Admin Console and go to the Account Management Realm's Advanced Settings.
- On the Workflow tab, enable PW Throttling if administrators need to be able to clear PW Throttling attempts.
- On the Multi-Factor Methods tab, enable MFA Throttling if administrators need to be able to clear MFA Throttling attempts.
Cause 2: Account Management Realm Uses an Incompatible Theme
The Account Management Realm must use the SA-IdP Theme, or a Theme built from the SA-IdP Theme, for clearing Throttling entries to take effect correctly. If the realm is using a different Theme, the clear action does not take effect and the user remains blocked.
Resolution 2:
To resolve this:
- Open the Admin Console and go to the Account Management Realm's Overview tab.
- Check which Theme is currently assigned to the realm.
- If the assigned Theme is not the SA-IdP Theme or a Theme built from it, change the realm to use the SA-IdP Theme, or rebuild the custom Theme from the SA-IdP Theme base.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.