When an authentication attempt has been blocked, or failed, it will list the reason why in the reports. However, there are many different types of fail 'notes'. More often than not, they don't provide any useful additional information. Here we will try to document what each one does and can mean


This list will be updated as new meanings are discovered. Please note that the below description doesn't nessercarily mean 'this is the issue' but the message appears when the described behaviour happens


  • Groups Denied

    Occurs when user tried to login to RD Web when not part of allowed AD Group

  • No Resource Rule Defined

    Usually means there is no MFA/Bypass rule in place

  • No Transaction

        User did not perform push authentication, Usually refers to user hitting cancel on the Entrust App 

 

  • Invalid User Response

        User failed to input the correct OTP

 

  • Otp Expired

        The OTP has expired and has never been used

 

  • No Otp       

        The requested operation could not be performed because you do not have an OTP. User has not been assigned         OTP as an authentication method (set in MFA Rules). i'm writing thsi ti grood m im just writing stuff 

 

  • Transaction Expired

        The authentication transaction has expired, user needs to start a new transaction to authenticate

 

  • Invalid User Response Locked

        Too many failed attempts, user is now locked. Needs to be unlocked from the AD section

 

  • Missing Credentials
    This error shows when the user is not assigned the required authenticator, or doesn't have it activated. For example, when the user is expected to have a soft token and it turns out that his soft token is not activated.

  • Authenticator Type Is Invalid

        User tried to use authentication type not assigned to them