Troubleshooting Multifactor Authentication
Error Message: Failed to exchange token
This error message occurs when there are multiple failed login attempts for MFA due to incorrect username or credentials.
Solution
Contact an administrator who controls access to the MFA provider. The administrator needs to unlock the user's account(s) to fix the problem.
User denied access to Multifactor Authentication
User is blocked from accessing Multifactor Authentication.
Solution
-
Your Windows remote access system logon account name, and your Multifactor Authentication account name, MUST be the same.
-
The MFA username, including the domain-name, (if provided, in the format domain\username), must exist on the MFA provider. If no domain is provided, CTE infers it as hostname\username.
"Unknown Certificate" warning from browser
When a remote user launches the browser for remote Multifactor Authentication, it generates a TLS handshake error for unknown certificate in the agent system log directory.
Solution
To prevent the Unknown Certificate
warning from a browser when accessing a remote endpoint, an administrator must import the certificate configured for remote Multifactor Authentication, to the CTE agent in the endpoint and in the browser configuration.
Multifactor Authentication Client Profile Failed on CipherTrust Manager enrollment**
Switching existing Multifactor Authentication Client Profile using register_host
failed on CipherTrust Manager enrollment.*
Work-around
- In CipherTrust Manager, change the existing Multifactor Authentication
Select MFA Exempted User Set
parameter to your new target user set