Most of the authentication mechanisims do not have a feature for authentication approval process by design. If AAF would able to do this enterprise customers can use it to approve user login to remote servers, vpns etc.
It is something like two step multi factor in which the OTP token request is first send to an approver, approver accepts or declines the request by clicking on the link via sms/email or decline with push notification via netiq authenticator etc. If ıt is approved, the token is sent to the requesting user else a declined notification or sms/email is sent to the user.


  • This is interesting.

    This type of process is being used via API by a client today.

    How would you see this work? Via push notification (smartphone method)?

    How would AA know who the approver was for a specific user?
