• Votes

    9

    Ability to reorder chains within an event

    Current situation: If you have an event with multiple chains and you want to change the order of the chains, you need to remove the chains (send them back to the ...

  • Votes

    9

    Login screens should, per-computer + per-user, remember last Chain ...

    Windows/Mac/Linux Client login screens should, per-computer and per-user remember the last Chain successfully used to login/unlock that device by that user, highlighting ...

  • Votes

    9

    Audit logging of configuration changes

    It would be beneficial to have an audit log of configuration changes (repositories, methods, chains, events, endpoints, etc.) to have some accountability and for ...

  • Votes

    9

    Customize wording inside user facing interfaces

    Looking to customize verbiage inside user facing web interfaces to match either internal language/references or technical level of staff. For instance: "<p>Welcome to ...

  • Votes

    9

    Add a "password never expires" option for the local user repository

    We need this option for the local Admin Account. The local Admin Account's password expires as any other user account. Please add a "password never expires" option to the ...

  • Votes

    9

    Align input centrally on login page

    The current login screen with user name and password is displayed at the top of the page. It would be better to display the field centrally, as this is more visible on ...

  • Votes

    9

    Ability that an enroll admin can only manage users from specific ...

    Today every enroll admin can set or change methods for every user. This can be a security risk. We would like to have the ability that an enroll admin can only manage ...

  • Planned

    9

    Allow enroll admins the ability to unlock user accounts

    When a user is locked out according to the Lockout policy, it would be desirable for someone with enroll admin role to be able to unlock a user. Typically unlocking users ...

  • Votes

    9

    Ability to deactivate self enrollment for specific methods

    In some cases it is desirable if a admin can configure that it is not possible for an user to (over)write specific methods in the self enrollment. For more flexibillity ...

  • Votes

    8

    Allow for customization of labels when using TOTP

    Typically, when you enroll a device using a TOTP authenticator app like Google's or Microsoft's, after you enroll, the account shows up with the name of the application ...

  • Votes

    8

    IPv6 support

    We are running in a dual stack environment and we need AAF as a product to support IPv6 in addition to IPv4.

  • Planned

    8

    Extend Radius server by PEAP support

    Currently Radius server supports only PAP while new (esp. mobile) devices use PEAP. It's the reason customers may not use AA for Radius & mobile device combination and ...

  • Votes

    8

    1:n matching for Fingerprint

    Requested by: several customers Currently 1:n matching is supported for the card and PKI methods. Our customers also want this for fingerprint authentication as well.

  • Planned

    8

    Smartphone Enrollment - Provide ways to seed Username and Description

    When user scans the QR they are prompted to enter username and description. Would like ability to customize where you use: Username: %REPO%\%USERNAME% Description: ...

  • Votes

    8

    Support AD Global Catalog in AAF

    As customers tend to have many ADs in their forest, we need support for global catalog functionality for AAF by using LDAPS on 3269. ...

  • Votes

    8

    AA should allow for an intelligent combination of Fingerprint and ...

    AA should allow for an intelligent combination of Fingerprint and Windows Hello within a Chain, in addition to also some other unrelated method like LDAP Password. By ...

  • Votes

    8

    Should be able to define multiple CSS/branding customizations on the ...

    Should be able to define multiple CSS/branding customizations on the same AA webserver, auto-enforced by the AA webserver based on the incoming HTTP Request “Host” ...

  • Votes

    8

    AA Admin console’s GUI to perform a full AA data backup should, in ...

    AA Admin console’s GUI to perform a full AA data backup should, in addition to the already upcoming AA feature to make the backup a schedulable item in the GUI, also ...

  • Votes

    8

    Use SSL for AD repository DNS discovery

    When using DNS discovery for AD repositories, there should be an option to add them as SSL-enabled on port 636. Today when using DNS discovery for AD repositories, they ...

  • Votes

    8

    Customize RADIUS Reply-Messages per method in a chain

    Applications that correctly implement RADIUS will show the Reply-Message value sent from the AAF server when authenticating with a chain. Right now, the Reply-Message ...