• Planned

    5

    Modify Client Login Extension

    We would like to request the client login extension link be shown before chain selection in the Windows agent. Currently it only shows up if the user selects the LDAP ...

  • Votes

    4

    Allow Events to be configured to use a default repo (if desired) that ...

    For our linux clients we need the option to either have an event ignore the login options list of repositories and use a default repo set at the event level or we need ...

  • Votes

    2

    Apply Advanced authentication by IP or wireless network (Windows ...

    Hi Our client asks if the second factor can be applied only to users who are out of the office. They have the NAAF client installed on their Surface equipment and they ...

  • Votes

    1

    only allow smartphone to access from the internet

    Some, especially small companies, do not have a SPI-firewall or reverseproxy-server. Nobody should get access to the AA server from the internet, except...Smartphones. ...

  • Votes

    1

    Automatic configuration Script

    For a typical GM installation with AD, Radius, and say Smartphone, there are actually not so many parameters to do the installation. It still takes many steps, and things ...

  • Votes

    7

    Configurable Offline OTP Cache Size

    We have laptops setup to use 2 factor authentication on logon. Windows natively handles the caching of AD credentials properly (and can be configured via group policy). ...

  • Votes

    7

    Combine some AAF client login screens the login process is to heavy

    AAF login screen 1 username input AAF login screen 2 chain selection input AAF login screen 3 password input AAF login screen 4 other method input For example ...

  • Votes

    2

    AdminGUI “Endpoints” screen - Needs to tell you how many total ...

    AdminGUI “Endpoints” screen - Needs to tell you how many total endpoints are currently registered

  • Votes

    2

    SMS/Voice methods allow for no-confirmation-required abuse when ...

    Security vulnerability: the SMS and Voice methods allow for no-confirmation-required abuse when “registering” phone numbers via the Authenticators Management portal. Just ...

  • Votes

    2

    poorly worded and inappropriate guidance on the SMS and Voice OTP ...

    Need the ability to edit the poorly worded and inappropriate guidance on the SMS OTP and Voice OTP enrollment screens (see screenshots below)? I don’t see a “Policies à ...

  • Votes

    2

    AA Windows Client needs to filter Chains based on hardware that AA ...

    The AA Windows Client needs to filter available Chains list based on the availability of locally present hardware that the AA Device Service detects as available. Right ...

  • Votes

    8

    Should be able to define multiple CSS/branding customizations on the ...

    Should be able to define multiple CSS/branding customizations on the same AA webserver, auto-enforced by the AA webserver based on the incoming HTTP Request “Host” ...

  • Votes

    10

    AA should have an option for customers to choose to completely ...

    AA should have an option for customers to choose to completely eliminate the mandatory Endpoint trust relationship mechanism built into AA thick clients (Win/Mac/Linux). ...

  • Votes

    5

    AA should have a well-thought out configuration option for explicitly ...

    AA should have a well-thought out configuration option for explicitly designated AA Webserver role servers to turn off access to all portals ...

  • Votes

    8

    AA should allow for an intelligent combination of Fingerprint and ...

    AA should allow for an intelligent combination of Fingerprint and Windows Hello within a Chain, in addition to also some other unrelated method like LDAP Password. By ...

  • Votes

    8

    AA Admin console’s GUI to perform a full AA data backup should, in ...

    AA Admin console’s GUI to perform a full AA data backup should, in addition to the already upcoming AA feature to make the backup a schedulable item in the GUI, also ...

  • Planned

    5

    Add more than one bluetooth authenticator device

    Customer ask for ability to configure more than one bluetooth device as an authenticator. For example, to use either smart watch or smartphone.

  • Votes

    3

    Configure endpoint whitlist based on ad group

    We would like the ability to configure endpoints whitlist based on ad/eDirectory group, not by specifying the endpoints directly.

  • Votes

    3

    NAAF Client 5.6 should get the language for a parameter that it can be ...

    NAAF Client 5.6 should get the language for a parameter that it can be changed by the end user. In our case the system locale can only be changed by the administrator and ...

  • Votes

    1

    Retrieve and accept user names in different format

    Some applications/systems use naming schema different then simple username. Good example might be FUDO running in "bastion" mode. In that case username consists of two ...