• Votes

    6

    Provide PKCS#11 (SmartCard) Libraries automatically

    Please provide several PKCS#11 Libraries (Safenet[Gemalto,Axalt,...], OpenSC, CardOS, YubiKey, etc) automatically with the Device Service. This makes it easier to use ...

  • Votes

    7

    Ability to enroll Windows Hello Fingerprint / Face Recognition ...

    Provide the ability to easy enroll the Windows Hello "Face Recognition, Fingerprint, etc" directly with the self enrollment portal. Provide also the ability to do this ...

  • Votes

    6

    Igel ThinClient Support

    It will be great if Igel ThinClients will be supported. We expect more than 10.000 Users which will need this.

  • Votes

    7

    Helpdesk - Granular access rights for enrolladmin to edit users

    Today every Enroll-Admin can change all authenticator of every users. This may cause a security issue. Which means that an enroll admin can take over an account from ...

  • Votes

    7

    Helpdesk - Two-Eyes procedure to change authenticator from user

    In regard to this Idea: https://ideas.microfocus.com/MFI/advance-authentication/Idea/Detail/15336 It would be good if there is an option to define which groups need a ...

  • Votes

    5

    Gernerate OTPs for other Services with the OTP Tool

    Customers wish an ability to generate OTPs for other services with the OTP Tool.

  • Votes

    3

    Ability to specify the shortname deliminator and placement

    For a RADIUS Server event, you can specify multiple chains which is very helpful in allowing the user to choose the best method to which they have enrolled - similar to ...

  • Votes

    6

    TACACS support

    It would be great to support TACACS integration, not only RADIUS. Many network devices today are configured using TACACS, not RADIUS.

  • Votes

    4

    Allow AAF to import branding from Access Manager automatically

    Hi guys, Can we please update the https://aafapp.demo.live/admin#/policies/WebAuthOptions page so that it can automatically download the standard branding from Access ...

  • Votes

    1

    Integrate in NAAF similar functionnality as eDirectory HOTP function

    Actually eDirectory offer a way to make 2 factor authentication using a simple LDAP bind. User concatenate their password with the HOTP code (mypassword123456). Some ...

  • Votes

    7

    Add integration with Cisco VPN as part of the AAF documentation

    Similar to OpenVPN, we have done a few integrations between AAF and Cisco AnyConnect (VPN) so we could have these steps as part of the documentation for AAF and we could ...

  • Votes

    14

    Azure Active Directory Integration for conditional access

    Would like to see that we can integrate Advanced Authentication with Microsoft Azure Active Directory conditional access policies to add two-factor authentication to ...

  • Planned

    4

    Logon Filter for "other" directories

    A potential customer is looking for the logon filter feature but for non-AD directories, in their case an Apple OpenDirectory (a fork of openLDAP). This could as well be ...

  • Votes

    2

    Add Gemalto Safenet Seedfile format

    We have a customer wanting to replace a 350 user Gemalto Token Solution for Citrix Netscaler Login. They would like to keep on using the token hardware but Gemalto has a ...

  • Votes

    8

    Support AD Global Catalog in AAF

    As customers tend to have many ADs in their forest, we need support for global catalog functionality for AAF by using LDAPS on 3269. ...

  • Votes

    2

    Resend OTP

    In our current scenario SMS contract is used as default authentication contract for user to login into the portal. When a user trying to login SMS Password is asking, ...

  • Votes

    6

    Support for RSA's Next Token Mode

    RSA SecurID Access has Next Token Mode. This is where the user may be challenged to provide a second token code on their RSA keyfob after providing a first one due to ...

  • Votes

    4

    Specify chain through RADIUS attribute

    For RADIUS Server event, you can specify multiple chains. As part of the RADIUS challenge-response authentication, it is possible to explictly define a chain to ...

  • Votes

    4

    Multi-language support for Twilio

    Twilio supports many different languages for their text-to-speech converter. This is a simple extension to the current Twilio configuration in AAF. At ...

  • Votes

    3

    Set user attribute in repository after enrollment (LDAP hook)

    Often AAF is working in conjunction with Identity Management / Access Management systems. In these cases it is desirable to know when users have enrolled (one or more) ...