• Votes

    7

    Configurable Offline OTP Cache Size

    We have laptops setup to use 2 factor authentication on logon. Windows natively handles the caching of AD credentials properly (and can be configured via group policy). ...

  • Votes

    6

    Option to enable automatic email to send reports to admins

    Option to send email with reporting to specific emails. ability to schedule reporting e.g. once a week to generate report with user activity etc.

  • Votes

    6

    Syslog messages for failed attempts to AdminUI and Helpdesk events due ...

    Current situation: Today, when a user attempts to login to the AdminUI and authenticates successfully but does not have the proper authorization (i.e. does not have the ...

  • Planned

    6

    Hide offline OTP option if offline OTP is disabled in Smartphone ...

    Current situation: When offline OTP is disabled for the Smartphone method, the user is still presented the ability to authenticate with the offline OTP at the AAF web ...

  • Votes

    6

    Add date/time parameter for Email OTP method

    We want to have the ability to configure date/time parameter. Currently we're limited in what we can configure in the email template. By sending date/time, users can for ...

  • Planned

    6

    search field for locked user for the helpdesk portal / ability to ...

    It would be a good to add these two features. 1) Add search field to search for users in the locked users-list 2) If a user will be opened in the help desk (where you can ...

  • Votes

    6

    Configuration of Windows Client through command line arguments at ...

    The Windows Client must be configured/customized post installation through the config.properties file. For options where it makes sense, it would be beneficial to ...

  • Votes

    6

    Use STARTTLS for LDAP-based repositories

    LDAP supports STARTTLS to encrypt communications using TLS. STARTTLS begins as a plaintext connection over the standard LDAP port (389), and that connection is then ...

  • Planned

    6

    Forward other logs besides Syslog

    We would like to be able to forward more than just the 'Syslog' log to a syslog server. We find the other logs having valuable information and being able to forward all ...

  • Votes

    6

    Regenerate endpoint id and secret without having to delete and ...

    It would be convinenet to be able to regenerate an Endpoint's id and secret instead of the current process of having to delete the endpoint and re-creating it. When ...

  • Votes

    6

    Provide a country code dropdown when enrolling in SMS OTP

    The user should be provided a dropdown box with a list of country codes that they must select before they can save their phone number for the SMS OTP. This forces their ...

  • Votes

    6

    Event Based Lockout Policies

    We would like to see event based lockout policies with the ability to configure different lockout attempt thresholds and durations and not effect other events for the ...

  • Votes

    5

    Windows Client set default Domain in config.properties

    Add an option to the Windows Client to set a default Domain in config.properties. Example: defaultDomain: DOMAINNAME Expected behaviour: The user types USERNAME (without ...

  • Votes

    5

    Add NAS-IP-Address to Radius event

    Please add NAS-IP-Address (Attribut-Type 4) to Radius event. Because some Appliances (as example Cisco ASA) do not support NAS-Identifier.

  • Votes

    5

    Option to hide QR Code in TOTP enrollment

    It would be a good feature if there is an option to disable the QR-Code or hide the QR Code, if TOTP method is enrolled. If a user re-open an enrolled T-OTP over the ...

  • Votes

    5

    Check if firewall ports are open

    We would prefer an Option to check if needed Firewall Ports are open. In our opinion this check-up can be located in the Management Consol of AAF. Additionally there ...

  • Votes

    5

    Using the Smartphone app push notification to Accept/Decline ...

    During enrollment, we don't have a notification of the enrollment process that is acknowledged by the user being enrolled. So far the methods we have assume that the ...

  • Votes

    5

    Support for Configuring SMS Sender Policy Using a JSON Body or CURL ...

    Currently when configuring the SMS Sender policy we only support submitting parameters in the http request URL. I was working with a customer that uses Avaya as their ...

  • Votes

    5

    Define authentication levels for each individual chain

    We have an enterprise access management/SSO application (ForgeRock OpenAM) used to protect web applications. We are looking to integrate Advanced Authentication with it ...

  • Votes

    5

    AA should have a well-thought out configuration option for explicitly ...

    AA should have a well-thought out configuration option for explicitly designated AA Webserver role servers to turn off access to all portals ...