• Votes

    6

    Option to enable automatic email to send reports to admins

    Option to send email with reporting to specific emails. ability to schedule reporting e.g. once a week to generate report with user activity etc.

  • Votes

    6

    TACACS support

    It would be great to support TACACS integration, not only RADIUS. Many network devices today are configured using TACACS, not RADIUS.

  • Votes

    6

    ability to disable biometrics or pin requirement on smartphone method ...

    Currently the require pin and require biometrics are set to true by default and when you set these to false this only allows users to disable this on there phone but it ...

  • Votes

    6

    Add the ability to restrict authentication to only managed devices

    Customer would like the ability to restrict mobile device (specifically Smartphone method) to ONLY devices that are currently being managed by an MDM solution. In this ...

  • Votes

    6

    Syslog messages for failed attempts to AdminUI and Helpdesk events due ...

    Current situation: Today, when a user attempts to login to the AdminUI and authenticates successfully but does not have the proper authorization (i.e. does not have the ...

  • Votes

    6

    Offline Update for AAF

    It would be nice if you make a solution to update AAF with an offline file over the Web Management Console (9443). Reason: In some customer environments it is not ...

  • Votes

    6

    Provide Advanced Authentication as .ova in addition to .iso

    The Advanced Authentication appliance is only available as an .iso. In addition to .iso, we would like to have Advanced Authentication provided as an .ova in addition to ...

  • Planned

    6

    Hide offline OTP option if offline OTP is disabled in Smartphone ...

    Current situation: When offline OTP is disabled for the Smartphone method, the user is still presented the ability to authenticate with the offline OTP at the AAF web ...

  • Votes

    6

    Add date/time parameter for Email OTP method

    We want to have the ability to configure date/time parameter. Currently we're limited in what we can configure in the email template. By sending date/time, users can for ...

  • Planned

    6

    search field for locked user for the helpdesk portal / ability to ...

    It would be a good to add these two features. 1) Add search field to search for users in the locked users-list 2) If a user will be opened in the help desk (where you can ...

  • Votes

    6

    Add Healthcheck URL for Load Balancing

    The current solution for a load balancer to determine the status of an AA web server is to build rules based on the AAF published API. Suggest adding a single ...

  • Votes

    6

    Configuration of Windows Client through command line arguments at ...

    The Windows Client must be configured/customized post installation through the config.properties file. For options where it makes sense, it would be beneficial to ...

  • Votes

    6

    Provide PKCS#11 (SmartCard) Libraries automatically

    Please provide several PKCS#11 Libraries (Safenet[Gemalto,Axalt,...], OpenSC, CardOS, YubiKey, etc) automatically with the Device Service. This makes it easier to use ...

  • Votes

    6

    Support RADIUS Authentication Methods CHAP and MS-CHAP

    Our IT-Security Department forbid the usage of PAP because of severe security issues. Please support at least MS-CHAP, otherwise we can't use the AA RADIUS for our ...

  • Votes

    6

    AAF Webserver without directly connection to LDAP

    In adition to https://ideas.microfocus.com/MFI/advance-authentication/Idea/Detail/14920 It would be very nice if an AAF Webserver may check user data directly over their ...

  • Votes

    6

    Use STARTTLS for LDAP-based repositories

    LDAP supports STARTTLS to encrypt communications using TLS. STARTTLS begins as a plaintext connection over the standard LDAP port (389), and that connection is then ...

  • Planned

    6

    Forward other logs besides Syslog

    We would like to be able to forward more than just the 'Syslog' log to a syslog server. We find the other logs having valuable information and being able to forward all ...

  • Votes

    6

    Regenerate endpoint id and secret without having to delete and ...

    It would be convinenet to be able to regenerate an Endpoint's id and secret instead of the current process of having to delete the endpoint and re-creating it. When ...

  • Votes

    6

    Support for RSA's Next Token Mode

    RSA SecurID Access has Next Token Mode. This is where the user may be challenged to provide a second token code on their RSA keyfob after providing a first one due to ...

  • Votes

    6

    Provide a country code dropdown when enrolling in SMS OTP

    The user should be provided a dropdown box with a list of country codes that they must select before they can save their phone number for the SMS OTP. This forces their ...