SAP Knowledge Base Article - Preview

3789422 - Sequences of error messages for Password and Passkey login when TFA is enabled with required fields in schema

Symptom

  • TFA is enabled.
  • There are required fields.
  • During login flow verification, the evaluation order of backend checks differs by authentication method.
  • Password (site id/password):
    • TFA is evaluated first and returns error 403101 or 403102 Account Pending TFA Verification.
    • Only after completing TFA, required fields validation returns error 20600 Account pending registration.
  • Passkey: Required profile fields validation is evaluated first and returns error 206001 before any TFA message.


Read more...

Environment

  • SAP Customer Data Cloud
  • Customer Identity
  • Risk-Based Authentication (RBA)

Product

SAP Customer Data Cloud all versions

Keywords

tfa, two-factor authentication, passkey, webauthn, screen-sets, error 403101, error 403102, error 206001, required fields, schema validation, login flow, evaluation order, accounts.login, finalizeRegistration, cdc, Gigya , KBA , CEC-PRO-API , Core REST API & Server SDKs (JWT / PHP / Java) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.