• Planned

    12

    Allow the AAF smartphone app to acceptance requests from the locked ...

    Allow the AAF smartphone app to acceptance requests from the locked phone screen

  • Votes

    11

    Better Health Check

    We desire the ability for web servers to have their health checked regularly to see if they can process authentication attempts. If not, the web server should be disabled ...

  • Planned

    11

    authenticator sharing

    Allow a shared authenticator to be used regardless of whether or not the the account it is shared with has the same authenticator enrolled or not. For example, if a ...

  • Votes

    10

    Audit logging of actions by Enroll Admins in the Helpdesk console

    All actions of Enroll Admins within the Helpdesk console should be logged -- information should include at least which authenticator for which user by a particular Enroll ...

  • Votes

    10

    SMS-OTP Authenticator allows letters and special characters in the ...

    Currently, users can also enter letters and special characters in the phone number input field. This of course leads to the fact that the telephone numbers cannot be ...

  • Votes

    9

    Windows local user password change using Forgotten Password ...

    Using forgotten password service ( over forgotten password link) with AAF Client version allows change password for Cached and Network password only in the first ...

  • Votes

    9

    RISK Engine only show single chain based on RISK level

    Currently with RISK if a user is "LOW" RISK they see 3 Chains to select. Would like to have ability to only show the single chain based on RISK. When the user is LOW ...

  • Votes

    9

    Login screens should, per-computer + per-user, remember last Chain ...

    Windows/Mac/Linux Client login screens should, per-computer and per-user remember the last Chain successfully used to login/unlock that device by that user, highlighting ...

  • Votes

    8

    IPv6 support

    We are running in a dual stack environment and we need AAF as a product to support IPv6 in addition to IPv4.

  • Planned

    8

    Extend Radius server by PEAP support

    Currently Radius server supports only PAP while new (esp. mobile) devices use PEAP. It's the reason customers may not use AA for Radius & mobile device combination and ...

  • Votes

    7

    Support FIDO 2 for Windows Authentication

    AAF supports only FIDO2 for webauthentication. Please add support for FIDO2 authentication in the windows login.

  • Votes

    6

    ability to disable biometrics or pin requirement on smartphone method ...

    Currently the require pin and require biometrics are set to true by default and when you set these to false this only allows users to disable this on there phone but it ...

  • Votes

    5

    Use the NetIQ iOS app to generate one time passwords from a YubiKey ...

    We would like it if the NetIQ implemented the Yubico iOS SDK so that our users could use a single app for the smartphone method and also to get YubiKey one time ...

  • Votes

    5

    device service should give error that bluetooth is not present

    The device service should give an error message if bluetooth device is not present like the device service does when a card reader is not present. Otherwise when a user ...

  • Votes

    5

    Brute force / BOT Attack and Data leakage Prevention

    A change in authentication flow can help prevent brute force bot attacks: 1. Information leakage - valid usernames & passwords discovery 2. User lockout due to bad ...

  • Votes

    5

    Improve Client Log rotation

    Please improve the client log rolling The debugging of a sporadically issue is very worse if the logging is running several days/weeks. Today for the naming of the log ...

  • Votes

    5

    Temporarily block user account after x failed attempts – when endpoint ...

    Feature: Being able to configure the system to temporarily block user account after x failed attempts (for instance account could be blocked for 30mn after 5 failed ...

  • Planned

    5

    AAF smartphone app should allow you to copy the TOTP enrollments

    AAF smartphone app should allow you to copy the TOTP enrollments

  • Votes

    5

    Extend REST-API - Assign User to existing OTP Token or Bulk import

    Please add these two functions in the Rest-API 1) Assign Users to an Existing OTP Token which is imported 2) Import for OTP tokens with Serialnumber & set a flag to make ...

  • Votes

    4

    Mobile application for Android Face-Unlock option

    Since more and more Android mobiles are providing face unlock option it would be great to have face unlock as an additional option for the existing pin & fingerprint ...