• Votes

    6

    Support RADIUS Authentication Methods CHAP and MS-CHAP

    Our IT-Security Department forbid the usage of PAP because of severe security issues. Please support at least MS-CHAP, otherwise we can't use the AA RADIUS for our ...

  • Votes

    6

    Support for RSA's Next Token Mode

    RSA SecurID Access has Next Token Mode. This is where the user may be challenged to provide a second token code on their RSA keyfob after providing a first one due to ...

  • Votes

    5

    Allow for customization of labels when AD password is not sync

    Typically, when you change your AD password, you have a message displayed after you successfully logon (OS or Mac Logon) which indicates: ‘"Enter password for sync". We ...

  • Votes

    5

    Gernerate OTPs for other Services with the OTP Tool

    Customers wish an ability to generate OTPs for other services with the OTP Tool.

  • Votes

    4

    Just in time import of SMS OTP and MAIL OTP when available on LDAP

    When using LDAP attribute to autocreate SMS OTP and Mail OTP methods, they are imported with delay If a customer has alternive ways to enroll SMS OTP and Mail OTP ...

  • Votes

    4

    Dynamic SMS gateway

    If there are more than one SMS gateways being used by an organization, there needs to be a dynamic configuration available for the same. The current example can if the ...

  • Votes

    4

    Allow AAF to import branding from Access Manager automatically

    Hi guys, Can we please update the https://aafapp.demo.live/admin#/policies/WebAuthOptions page so that it can automatically download the standard branding from Access ...

  • Votes

    4

    Allow for customization of labels when using TOTP

    Typically, when you enroll a device using a TOTP authenticator app like Google's or Microsoft's, after you enroll, the account shows up with the name of the application ...

  • Votes

    4

    Specify chain through RADIUS attribute

    For RADIUS Server event, you can specify multiple chains. As part of the RADIUS challenge-response authentication, it is possible to explictly define a chain to ...

  • Planned

    4

    Alert on Security Patch

    Requested by: NXP Description: Ability to define email address(es) for alert of critical patches availability

  • Planned

    4

    Logon Filter for "other" directories

    A potential customer is looking for the logon filter feature but for non-AD directories, in their case an Apple OpenDirectory (a fork of openLDAP). This could as well be ...

  • Votes

    4

    Multi-language support for Twilio

    Twilio supports many different languages for their text-to-speech converter. This is a simple extension to the current Twilio configuration in AAF. At ...

  • Votes

    4

    Second Factor Skipping Assignment

    Requested by: CHS Description: Ability to assign skipping behavior by group (Physicians =16 hours, Clinicians =10hours, Administration =0hours)

  • Votes

    4

    Ability to use Repository Attribute as PIN

    Requested by: 7-11 Description: ability to assign an attribute (such as employee #) as default PIN

  • Votes

    3

    AA needs manual saml metadata configuration option

    AA’s SAML IDP capabilities right now only allows you to setup federation with a SAML SP’s via importing a SAML metadata file. Many SAML SP’s are unable to create ...

  • Votes

    3

    Support returnURL and returnUnregisteredURL after enrollment

    Sometimes NAA is integrated with other IDP. In these cases, a user may be sent to NAA just to enroll a specific method, for instance the user could be redirected to: ...

  • Votes

    3

    Basic auth for specific NAA resources

    Today it is possible to make use of basic auth just for Authenticators Management main page if enabled on its event Since it is the only supported way to do SSO with ...

  • Votes

    3

    Improve LDAP repo support to do fast scan during login and chain ...

    Use case: to be used whenever “Nesting support” is Disabled OR if the the directory is an eDirectory First call to retrieve user (& (objectClass=user) (| ...

  • Votes

    3

    Offline Authentication for VMware Horizon View

    VMware Horizon View doesn't allow offline authentication when using Mobile App / Radius event. It would be great to have the possiblity to enter OTP code from mobile app ...

  • Votes

    3

    Force Enrollment from Agents

    Requested by: Charter Description: Ability to force enrollment from workstation agents (Win, OSX, Linux)