• Votes

    4

    Dynamic SMS gateway

    If there are more than one SMS gateways being used by an organization, there needs to be a dynamic configuration available for the same. The current example can if the ...

  • Votes

    4

    Allow AAF to import branding from Access Manager automatically

    Hi guys, Can we please update the https://aafapp.demo.live/admin#/policies/WebAuthOptions page so that it can automatically download the standard branding from Access ...

  • Votes

    4

    Allow for customization of labels when using TOTP

    Typically, when you enroll a device using a TOTP authenticator app like Google's or Microsoft's, after you enroll, the account shows up with the name of the application ...

  • Votes

    4

    Specify chain through RADIUS attribute

    For RADIUS Server event, you can specify multiple chains. As part of the RADIUS challenge-response authentication, it is possible to explictly define a chain to ...

  • Planned

    4

    Alert on Security Patch

    Requested by: NXP Description: Ability to define email address(es) for alert of critical patches availability

  • Planned

    4

    Logon Filter for "other" directories

    A potential customer is looking for the logon filter feature but for non-AD directories, in their case an Apple OpenDirectory (a fork of openLDAP). This could as well be ...

  • Votes

    4

    Multi-language support for Twilio

    Twilio supports many different languages for their text-to-speech converter. This is a simple extension to the current Twilio configuration in AAF. At ...

  • Votes

    4

    Second Factor Skipping Assignment

    Requested by: CHS Description: Ability to assign skipping behavior by group (Physicians =16 hours, Clinicians =10hours, Administration =0hours)

  • Votes

    4

    Ability to use Repository Attribute as PIN

    Requested by: 7-11 Description: ability to assign an attribute (such as employee #) as default PIN

  • Votes

    3

    AA needs manual saml metadata configuration option

    AA’s SAML IDP capabilities right now only allows you to setup federation with a SAML SP’s via importing a SAML metadata file. Many SAML SP’s are unable to create ...

  • Votes

    3

    Support returnURL and returnUnregisteredURL after enrollment

    Sometimes NAA is integrated with other IDP. In these cases, a user may be sent to NAA just to enroll a specific method, for instance the user could be redirected to: ...

  • Votes

    3

    Basic auth for specific NAA resources

    Today it is possible to make use of basic auth just for Authenticators Management main page if enabled on its event Since it is the only supported way to do SSO with ...

  • Votes

    3

    Improve LDAP repo support to do fast scan during login and chain ...

    Use case: to be used whenever “Nesting support” is Disabled OR if the the directory is an eDirectory First call to retrieve user (& (objectClass=user) (| ...

  • Votes

    3

    Offline Authentication for VMware Horizon View

    VMware Horizon View doesn't allow offline authentication when using Mobile App / Radius event. It would be great to have the possiblity to enter OTP code from mobile app ...

  • Votes

    3

    Force Enrollment from Agents

    Requested by: Charter Description: Ability to force enrollment from workstation agents (Win, OSX, Linux)

  • Votes

    3

    Set user attribute in repository after enrollment (LDAP hook)

    Often AAF is working in conjunction with Identity Management / Access Management systems. In these cases it is desirable to know when users have enrolled (one or more) ...

  • Votes

    3

    Support U2F over SSH

    Requested by: NYC DOITT Description: Ability to use U2F over SSH

  • Votes

    3

    TOTP Enrollment with serial via public api

    We would like to enroll hardware TOTP tokens via public API with unprivileged session, in combination with token serial plus first OTP. Request example: ...

  • Votes

    3

    Ability to specify the shortname deliminator and placement

    For a RADIUS Server event, you can specify multiple chains which is very helpful in allowing the user to choose the best method to which they have enrolled - similar to ...

  • Votes

    2

    SMS/Voice OTP needs support for STOP/CANCEL callbacks

    When integrated with Twilio or similar SMS/Voice API providers included out-of-the-box with Advanced Authentication, to leverage higher volumes of outgoing SMS texts. ...