That is correct; the RSA token cannot be sent as a password and when using the RSA/ACE server type, the appliance will not send the credential.
To avoid users needing to provide the password, you will need to configure secondary authentication to get the password and then configure a file browsing SSO policy that uses and