• Votes

    3

    Ability to link AAF v6.x Configuration portal and Desktop OTP app to ...

    In multiple conversations with clients there is often the question around how does the NetIQ Smartphone App compares with Google authenticator and often enough the ...

  • Votes

    3

    LDAP Password Expired

    If the LDAP Password Expired, can we get an Option for Set a New Password in the Enrollment Center to change or set a new Password.

  • Votes

    3

    populate the AD domain\username after client is installed and prior to ...

    When a user fist logs into aaf after the client was first installed the user must enter the AD domain\username. It would be ideal if the aaf installer could find the ...

  • Votes

    3

    Option to use repositories instead of groups

    Everywhere we can limit something by group, it would be nice to be able to limit by repository as well. We have a repository that contains only user objects. We can ...

  • Votes

    3

    Do not show chains with Smartphone method when client does not have a ...

    Related to https://ideas.microfocus.com/MFI/advance-authentication/Idea/Detail/14402 Current situation: When offline OTP for Smartphone method is disabled and the user ...

  • Votes

    3

    Provide option to disable the ability for the Enroll admin (Helpdesk) ...

    Currently a helpdesk admin can enroll/remove enrollments for his/her own user and some clients do see this as a potential risk. Could we perhaps have a policy, similar to ...

  • Votes

    3

    Device Fingerprint

    Hi, At the moment, we could define 2 Chains whereby Chain1 is LDAP Password+Smartphone and Chain2 is LDAP Password for example. Chain 1 is used for the 1st time and ...

  • Votes

    3

    Configurable grace period before a user is deleted from AA due to not ...

    Repositories will do a periodic sync. A user is deleted from an AA repository if they are not returned in the result set of a repository sync. Deleting a user from AA is ...

  • Votes

    3

    Want a way to get a report on linked credentials

    So want to know is there a way to get a report on linked credentials 2018-10-04T14:18:38.864705 (UTC+0000)+00:00 aafapp CEF:0|AAA|Core|5.0|101|User was successfully ...

  • Votes

    3

    Add simpleSAML to Appliance for testing and POC

    Would like ability to have simpleSAML on appliance. Mainly quick and simple to setup and test. As a reference the following I found in the Internet just do not like the ...

  • Votes

    3

    TOTP Enrollment with serial via public api

    We would like to enroll hardware TOTP tokens via public API with unprivileged session, in combination with token serial plus first OTP. Request example: ...

  • Votes

    3

    CEF Log Forward Policy Increase the Number of Servers

    Today we have the Option to set only one Server. But if we can increase the number of servers, we have the option to spread the logfiles. This would a better solution ...

  • Votes

    3

    Native U2F Support beyond chrome browser

    Since chrome support for FIDO U2F was added some time ago but now other browsers like Firefox support it as well. While it does work if enabled manually on older firefox ...

  • Planned

    3

    Reduce privileges for device service on Windows

    Hello, When device service is installed on Windows, it installs a windows service that runs with local\system account permissions. We want to be able to run it using a ...

  • Votes

    3

    Disable modification of automatically enrolled Authenticators in the ...

    Some Authenticators are automatically created by Advanced Authentication, e.g. LDAP password. If you click on the Authenticator in the Self-Service portal, the Edit page ...

  • Planned

    3

    A way to delete OATH seed-files more than one per selection.

    A way to delete OATH seed-files more than one per selection. If we would get a checkbox for the selection of the file to be deleted. To delete several Seed-files at once.

  • Votes

    3

    automatic re-enrollment

    When a user has installed the AA Smartphone app, if they reset their phone, when they re-install and re-enroll it will be a separate enrollment; the original enrollment ...

  • Votes

    3

    Ability to specify the shortname deliminator and placement

    For a RADIUS Server event, you can specify multiple chains which is very helpful in allowing the user to choose the best method to which they have enrolled - similar to ...

  • Votes

    3

    Configure endpoint whitlist based on ad group

    We would like the ability to configure endpoints whitlist based on ad/eDirectory group, not by specifying the endpoints directly.

  • Votes

    3

    configurable methods or adding custom methods with different ...

    We want through the methods settings yesterday and when looking into the fingerprint options there was a threshold value to be adjusted. Some other adjustments in other ...