Summary
This article defines the common reasons for "Access Denied" events within the system and guides interpreting specific error codes. It covers credential-based issues (such as expired or unknown cards), permission-based issues (such as time schedule or location restrictions), and security-related violations (such as passback or tailgate errors) to assist in rapid troubleshooting.
Body
Overview
This article explains why a user may receive an "Access Denied" message at a door reader and provides a guide to interpreting the specific reason codes logged in the system.
Symptoms
A user may encounter one of the following at a reader location:
- An "Access Denied" message is displayed on the reader.
- An "Access Denied" or "Unknown Card" entry appears in the Activity Log.
- An "Access Not Completed" entry appears (occurs when credentials are presented but the door is not opened).
Common Denial Reasons (Reason Codes)
Credential Issues
- [UNKNOWN]: The card's data format is valid, but there is no record of this credential in the system.
- [BIT MISMATCH]: The credential data format does not match any format configured in the system (often related to Mercury panel configurations).
- [DISABLED]: The credential has been manually disabled (also applies to statuses such as [STOLEN], [LOST], [SUSPENDED], or [NOT RETURNED]).
- [EXPIRED]: The credential has passed its assigned end date.
- [NOT USED]: The credential was disabled because it exceeded the maximum allowed days of non-use.
Access & Permission Issues
- [TIME]: The user's Time Spec does not allow access at the current time.
- [WRONG DAY]: The user's Time Spec or Holiday definition does not allow access on this specific day of the week.
- [LOCATION]: The user's Access Level or the current system Threat Level does not permit use of this specific reader.
- [NO ESCORT]: The user holds a "Requires Escort" access level and did not have an authorized escort present within the required 15-second window.
Security & Protocol Issues
- [PASSBACK VIOLATION]: The credential was presented to enter a region where the user is already known to be.
- [TAILGATE VIOLATION]: The credential was presented to enter a region where the user is known not to be.
- [PIN]: An invalid PIN was entered, or no PIN was entered within the configured timeout period ([NO PIN]).
- [THREAT LEVEL]: The current system Threat Level restricts this user's access level.
Investigation Checklist
When troubleshooting an access denial, please verify the following:
- Check the Activity Log: Identify the specific Reason Code provided in the log entry.
- Verify the Person Record: Ensure the user has an active status and the correct Assigned Access Level.
- Verify the Schedule: Check the Time Specs and Holiday definitions to ensure the time/day is valid for that user.
- Check the Reader: Ensure the reader is correctly associated with the expected Reader Group and Portal.