RSA ID Plus Service Incident <EMEA Region>

Incident Report for RSA ID Plus

Postmortem

Incident Summary

On January 15, 2026 06:45–07:15 UTC, a subset of customers hosted on the EU1 deployment in the EMEA region experienced a degradation in authentication services. The event primarily manifested as intermittent authentication disruption, with the majority of affected tenants experiencing impact for less than 40 minutes.

Core platform availability remained operational throughout the event. Most customers were able to authenticate successfully during the impact window, though some authentication flows experienced slower-than-normal response times and elevated failure rates for a limited period. Service behavior returned to normal once mitigation actions were applied.

Root Cause

A January service update introduced a flaw in our upgrade handling which caused some clients to unnecessarily retrieve application resources, creating unexpected request patterns within the authentication flow. This behavior disrupted normal request patterns within the authentication flow and contributed to authentication disruption for a subset of customers.

In addition, notifications on the status page occurred later than expected. During the incident, overall service availability remained operational, and the impact presented as intermittent authentication disruption rather than a sustained outage condition. Because successful authentications continued throughout the incident window for most customers, initial indicators aligned with a limited disruption scenario. Customer communication was issued as impact scope was confirmed.

Mitigation and Recovery Actions

During the incident, the following actions were taken:

  • Rolled back January service updates deployed prior to the incident
  • Scaled additional capacity within the affected EMEA deployment
  • Continued real-time monitoring to validate stabilization

These actions successfully stabilized the environment. No recurrence has been observed since mitigation was applied.

Corrective and Preventive Actions

The following actions are under evaluation or implementation:

  • Improvements to upgrade handling to prevent unnecessary resource refresh behavior
  • Enhancements to monitoring and alerting to improve visibility into customer-impacting disruption scenarios
  • Review of incident communication workflows and notification triggers
Posted Jan 23, 2026 - 18:48 UTC

Resolved

We have detected an issue affecting the RSA Cloud Authentication Services impacting those customers hosted on our EU1 EMEA deployment. Operations has determined that the incident affecting RSA ID Plus has been resolved.

As part of our mitigation efforts, the January service release has been rolled back in the affected EMEA environment. This action was taken as a precaution while our Engineering teams continue the root cause analysis.

Service behavior has remained stable since the rollback, and we are continuing to closely monitor the environment. Additional updates will be shared as they become available.

We will post a root cause analysis as soon as it is available.
Posted Jan 15, 2026 - 07:30 UTC