• Planned

    4

    Client OTP Application(s)

    Requested by: Multiple clients Description: Windows, OS X and Linux based thick applications for OTPs

  • Votes

    1

    Request New Token

    Requested by: Client Description: User should be able to report lost/stolen token and request replacement

  • Votes

    4

    Ability to use Repository Attribute as PIN

    Requested by: 7-11 Description: ability to assign an attribute (such as employee #) as default PIN

  • Planned

    21

    Ability to use Radius Attributes

    make Radius more configurable in AAF so that attributes can be changed / configured

  • Votes

    3

    configurable methods or adding custom methods with different ...

    We want through the methods settings yesterday and when looking into the fingerprint options there was a threshold value to be adjusted. Some other adjustments in other ...

  • Votes

    10

    Ability to use configurable LDAP queries

    depending of content of custom attributes like CUSTOMER_EMPLOYEE_TYPE either internal or external or 401k the customer wants to adjust LDAP queries and searches

  • Planned

    21

    Integrate AT citizen card ( Buergerkarte ) as authenticator

    the information around the citizen card are limited however you can have a look here: There are two options of the "Buergerkarte": As mobile ignatur and as Smart Card ...

  • Votes

    5

    Rolling over RADIUS authentication

    getting a possibility to check PIN + OTP on AA and once this is not accepting / valid fowarding the PIN and OTP to a 3rd party AAA server -> using then the Radius Client ...

  • Votes

    4

    view only admin category

    In the Admin UI there's currently no way to configure a "view only" account. Therefore a new role should be introduced so that a user can login on the Admin UI to reflect ...

  • Votes

    5

    Option to hide QR Code in TOTP enrollment

    It would be a good feature if there is an option to disable the QR-Code or hide the QR Code, if TOTP method is enrolled. If a user re-open an enrolled T-OTP over the ...

  • Planned

    6

    search field for locked user for the helpdesk portal / ability to ...

    It would be a good to add these two features. 1) Add search field to search for users in the locked users-list 2) If a user will be opened in the help desk (where you can ...

  • Votes

    9

    Ability to deactivate self enrollment for specific methods

    In some cases it is desirable if a admin can configure that it is not possible for an user to (over)write specific methods in the self enrollment. For more flexibillity ...

  • Votes

    5

    Extend REST-API - Assign User to existing OTP Token or Bulk import

    Please add these two functions in the Rest-API 1) Assign Users to an Existing OTP Token which is imported 2) Import for OTP tokens with Serialnumber & set a flag to make ...

  • Votes

    9

    Ability that an enroll admin can only manage users from specific ...

    Today every enroll admin can set or change methods for every user. This can be a security risk. We would like to have the ability that an enroll admin can only manage ...

  • Votes

    11

    Certificate filter - Hide expired certificates

    Please hide expired certificates in the "certificate list" during the PKI enrollment

  • Votes

    4

    Simplified authentication in offline mode

    With AAF it is possible to configure a Simplified authentication "Last logon tracking options". "This policy helps you to automatically move to a simple chain that ...

  • Planned

    10

    Support for more Linux distribution

    Some customer would like to integrate the AAF with other linux derivatives as example debian. So it is possible to get more security on environments with different ...

  • Votes

    2

    Check for the similarity of the new passwords with the password ...

    Method: Password New Option: Check for the similarity of the new passwords with the password history

  • Votes

    7

    Support FIDO 2 for Windows Authentication

    AAF supports only FIDO2 for webauthentication. Please add support for FIDO2 authentication in the windows login.

  • Votes

    10

    Ability for caching shared (linked) authenticators

    In reference to SR#101184179111 Today, AAF is not able to cache credentials on windows,linux, macos for users they are using shared (linked) authenticators. Please ...