Skip Navigation

Known issues

Issues that are new in this release are noted with an asterisk (*).

General known issues

* Software OTP tokens are not appearing in the 
BlackBerry UEM Client
 even though an appropriate 
BlackBerry 2FA
 profile has been assigned to the user. This issue affects 
BlackBerry UEM Client
 for 
Android
 version 12.34.0.154893 and earlier, and 
BlackBerry UEM Client
 for 
iOS
 version 12.38.2127 and earlier.
Workaround
: Update the 
BlackBerry UEM Client
 to the latest version.
When manually resyncing a hardware OTP token, if you enter the time-step window value that is just enough to accommodate the token, a success message appears even though it is not properly synced. The time-step window is not updated. (JI 2496282)
Workaround
: When entering the time-step window value, increase it by 1.
After successfully adding a 
BlackBerry 2FA
 server in the 
BlackBerry UEM
 management console, an error message appears when you click "Next". (JI 2250781)
Workaround
: On the menu bar, click 
Settings > External Integration > BlackBerry 2FA server
. In the server list, click the server that you added. 
When a 
BlackBerry 2FA
 prompt arrives to an 
iOS
 device that is locked or the screen is off, the timer starts after the device is unlocked or the screen is turned on, rather than when the prompt first arrived. (JI 839771, 821128)

BlackBerry 2FA
 server known issues

The following are the known issues for 
BlackBerry 2FA
 server.
When you add a new 
BlackBerry 2FA
 server and you copy the configuration settings from another server, the group assignments are also copied without warning. (JI 2193240)
When a VPN server is configured to use MS-CHAP v2 or EAP/MS-CHAP v2 authentication protocols, 
BlackBerry 2FA
 does not complete the second factor of authentication for a 
Microsoft Active Directory
 user if their email address does not match their the username. (JI 1639563)
When a VPN server is configured to use MS-CHAP v2 or EAP/MS-CHAP v2 authentication protocols, 
BlackBerry 2FA
 does not complete the authentication request for a 
Microsoft Active Directory
 user with the [user]@[domain] email address syntax. (JI 1637204) 
BlackBerry 2FA
 does not support an MS-CHAP v2 password change over RADIUS for a 
Barracuda
 SSL VPN gateway. (JI 1564368)
When you configure the 
BlackBerry 2FA
 server to support 
BlackBerry UEM
 high availability, if the 
BlackBerry 2FA
 server receives an error from the 
BlackBerry UEM
 server, it immediately tries the next server on the list and doesn't check the status code. (JI 865385)