Synchronize a soft token authenticator
If a user cannot authenticate with a soft token, there might be clock drift between the user's mobile device and IDaaS. Use Synchronize to realign the token. Before you begin, ask the user to confirm that the mobile device clock and carrier time are synchronized.
Synchronize a soft token authenticator
-
Click > Members > Users. The Users List page appears.
-
Click the user ID. The User Details page appears.
-
Click the Authenticators tab. The Authenticators page appears.
-
Click to the right of the soft token authenticator that you want to synchronize. A drop-down list appears.
-
Click Synchronize. The Synchronize Token dialog box appears.
-
Do one of the following:
If you have the mobile device:
- Open the soft token app (Entrust Soft Token or Google Authenticator).
- Enter the token response shown in the soft token app.
- Click Synchronize.
If you do not have the mobile device:
- Leave the token response field blank.
- Click Synchronize.
Validate your changes
After synchronization, validate the result.
- Confirm the user can sign in successfully with a new token response.
- Confirm repeated token attempts no longer fail due to time mismatch.
- If synchronization fails, confirm the device clock and carrier time are correct, then try again.
If the user still cannot authenticate after synchronization, clock drift is likely not the cause. Delete and reconfigure the authenticator on the mobile device and in IDaaS.