Add and configure On-Prem MFA/RSA SecurID
Before installing the agent, you must configure:
- MFA authenticators
- RSA SecurID or On-Prem MFA
Configure authenticators
- Sign in to your Okta tenant as an administrator.
- In the Admin Console, go to .
- Choose RSA SecurID or On-Prem MFA.
- Some authenticators have additional configuration options that you can configure from the list of added authenticators by clicking .
Configure On-prem MFA
- Enter the following fields:
- Provider name: This is the name that appears to end users during their login challenge.
- Username format: Select the format expected by the provider.
- Hostname: The server host name or IP address of the RSA server.
- Authentication Port: The RADIUS server port (for example 1812).
This is defined when the On-Prem RADIUS server is configured. - Shared Secret: An authentication key that must be defined when the RADIUS server is configured, and must be the same on both the RADIUS client and server.
- Click Add.
- Click Add New Agent.
Note the value of the instance ID.
You're also provided a download link for the on-prem MFA agent installer. - Activate or Deactivate the authenticator as required.
- Click Save.
Configure RSA SecurID
- Enter the following fields:
- Username format: Select the format expected by the provider.
- Hostname: The server host name or IP address.
- Authentication Port: The RADIUS server port (for example, 1812). This is defined when the On-Prem RADIUS server is configured.
- Shared Secret: An authentication key that must be defined when the RADIUS server is configured, and must be the same on both the RADIUS client and server.
- Click Add New Agent. Note the value of the instance ID. You're also provided a download link for the agent installer.
- Activate or Deactivate as required.
- Click Save.