Why was access door access denied?

Summary

This article defines the common reasons for "Access Denied" events within the system and guides interpreting specific error codes. It covers credential-based issues (such as expired or unknown cards), permission-based issues (such as time schedule or location restrictions), and security-related violations (such as passback or tailgate errors) to assist in rapid troubleshooting.

Body

Overview

This article explains why a user may receive an "Access Denied" message at a door reader and provides a guide to interpreting the specific reason codes logged in the system.

Symptoms

A user may encounter one of the following at a reader location:

  • An "Access Denied" message is displayed on the reader.
  • An "Access Denied" or "Unknown Card" entry appears in the Activity Log.
  • An "Access Not Completed" entry appears (occurs when credentials are presented but the door is not opened).

Common Denial Reasons (Reason Codes)

Credential Issues

  • [UNKNOWN]: The card's data format is valid, but there is no record of this credential in the system.
  • [BIT MISMATCH]: The credential data format does not match any format configured in the system (often related to Mercury panel configurations).
  • [DISABLED]: The credential has been manually disabled (also applies to statuses such as [STOLEN], [LOST], [SUSPENDED], or [NOT RETURNED]).
  • [EXPIRED]: The credential has passed its assigned end date.
  • [NOT USED]: The credential was disabled because it exceeded the maximum allowed days of non-use.

Access & Permission Issues

  • [TIME]: The user's Time Spec does not allow access at the current time.
  • [WRONG DAY]: The user's Time Spec or Holiday definition does not allow access on this specific day of the week.
  • [LOCATION]: The user's Access Level or the current system Threat Level does not permit use of this specific reader.
  • [NO ESCORT]: The user holds a "Requires Escort" access level and did not have an authorized escort present within the required 15-second window.

Security & Protocol Issues

  • [PASSBACK VIOLATION]: The credential was presented to enter a region where the user is already known to be.
  • [TAILGATE VIOLATION]: The credential was presented to enter a region where the user is known not to be.
  • [PIN]: An invalid PIN was entered, or no PIN was entered within the configured timeout period ([NO PIN]).
  • [THREAT LEVEL]: The current system Threat Level restricts this user's access level.

Investigation Checklist

When troubleshooting an access denial, please verify the following:

  1. Check the Activity Log: Identify the specific Reason Code provided in the log entry.
  2. Verify the Person Record: Ensure the user has an active status and the correct Assigned Access Level.
  3. Verify the Schedule: Check the Time Specs and Holiday definitions to ensure the time/day is valid for that user.
  4. Check the Reader: Ensure the reader is correctly associated with the expected Reader Group and Portal.

Details

Details

Article ID: 2361
Created
Fri 7/31/26 2:49 PM