• Votes

    7

    Add integration with Cisco VPN as part of the AAF documentation

    Similar to OpenVPN, we have done a few integrations between AAF and Cisco AnyConnect (VPN) so we could have these steps as part of the documentation for AAF and we could ...

  • Votes

    7

    Support FIDO 2 for Windows Authentication

    AAF supports only FIDO2 for webauthentication. Please add support for FIDO2 authentication in the windows login.

  • Votes

    7

    Deleting a Smartphone authenticator in the NetIQ app deletes the ...

    Current situation: If you delete a Smartphone authenticator from the Self-Service portal/server-side, the Smartphone authenticator on your NetIQ app is deleted. However, ...

  • Votes

    7

    Ability to enroll Windows Hello Fingerprint / Face Recognition ...

    Provide the ability to easy enroll the Windows Hello "Face Recognition, Fingerprint, etc" directly with the self enrollment portal. Provide also the ability to do this ...

  • Votes

    7

    Helpdesk - Enhancements

    1) User Logs: Show the IP-Adress from the accessing Radius Client (192.168.0.20, which can be a VPN Server, etc.) which sends the authentication request to AAF As an ...

  • Votes

    7

    Lets encrypt integration

    Not just for AAF, but also Filr etc it would be great to have support / automation possibility to use lets encrypt certificates.

  • Planned

    7

    Allow Windows Client (and Linux/Mac) to set locale in ...

    We have the need for certain Windows clients to have a specific locale set in the config.properties file. This should override the OS locale.

  • Votes

    7

    Helpdesk - Granular access rights for enrolladmin to edit users

    Today every Enroll-Admin can change all authenticator of every users. This may cause a security issue. Which means that an enroll admin can take over an account from ...

  • Votes

    7

    Helpdesk - Two-Eyes procedure to change authenticator from user

    In regard to this Idea: https://ideas.microfocus.com/MFI/advance-authentication/Idea/Detail/15336 It would be good if there is an option to define which groups need a ...

  • Votes

    7

    Kerberos Authentication for internal AD users

    It would be great, if we could allow internal AD members Kerberos integrated authentication.

  • Votes

    7

    Clear message when deleting authenticators

    Currently, when deleting an authenticator, a user only gets a message asking if he wants to continue. This can be confirmed with 'Ok' or canceled. Since this system is ...

  • Votes

    7

    Validate correct password when saving repository settings

    Every time you adjust the settings of a repository, you are required to provide a password for the user you are connecting as however there is no check to see if the ...

  • Votes

    7

    TOTP on Smartwatch

    Currently it is the case that the request for a TOTP via the smartphone also appears on a SmartWatch, but only as a message. It would be great if you could confirm the ...

  • Votes

    7

    Remove Copyright information in Login Screen

    Remove the Copyright information in Login Screen (Copyright © 2017 NetIQ. All rights reserved. Build: NAAF-5.6). For risk purposes, the product name should not be shown.

  • Votes

    7

    Combine some AAF client login screens the login process is to heavy

    AAF login screen 1 username input AAF login screen 2 chain selection input AAF login screen 3 password input AAF login screen 4 other method input For example ...

  • Votes

    7

    Display serial number of enrolled HOTP authenticator

    It would be beneficial for a user to see the serial number of their currently enrolled HOTP authenticator in the authenticators management portal. A user may have one or ...

  • Votes

    7

    Let's change eToken/Smartcard password on credential provider

    Now there is no possibility to change the eToken password at the credential provider. if the password is expired the user has to phone the Helpdesk to create a emergency ...

  • Votes

    7

    AdminGUI “Endpoints” screen - Needs to allow Helpdesk/ENROLL ADMINS ...

    AdminGUI “Endpoints” screen - Needs to allow Helpdesk/ENROLL ADMINS role the ability to access this screen. Today they can only see user enrollments, but an equal part of ...

  • Votes

    7

    Configurable Offline OTP Cache Size

    We have laptops setup to use 2 factor authentication on logon. Windows natively handles the caching of AD credentials properly (and can be configured via group policy). ...

  • Votes

    6

    Igel ThinClient Support

    It will be great if Igel ThinClients will be supported. We expect more than 10.000 Users which will need this.