• Votes

    6

    Event Based Lockout Policies

    We would like to see event based lockout policies with the ability to configure different lockout attempt thresholds and durations and not effect other events for the ...

  • Votes

    5

    Enable ability to customize AAF login page

    For AAF login page would like to be able to change the text “User name” to “Email Address” and “REPOSITORY\user” to Email Address” since we want the users to use email ...

  • Votes

    5

    Windows Client set default Domain in config.properties

    Add an option to the Windows Client to set a default Domain in config.properties. Example: defaultDomain: DOMAINNAME Expected behaviour: The user types USERNAME (without ...

  • Votes

    5

    Use the NetIQ iOS app to generate one time passwords from a YubiKey ...

    We would like it if the NetIQ implemented the Yubico iOS SDK so that our users could use a single app for the smartphone method and also to get YubiKey one time ...

  • Votes

    5

    Allow for customization of labels when AD password is not sync

    Typically, when you change your AD password, you have a message displayed after you successfully logon (OS or Mac Logon) which indicates: ‘"Enter password for sync". We ...

  • Votes

    5

    device service should give error that bluetooth is not present

    The device service should give an error message if bluetooth device is not present like the device service does when a card reader is not present. Otherwise when a user ...

  • Votes

    5

    Add NAS-IP-Address to Radius event

    Please add NAS-IP-Address (Attribut-Type 4) to Radius event. Because some Appliances (as example Cisco ASA) do not support NAS-Identifier.

  • Votes

    5

    Option to hide QR Code in TOTP enrollment

    It would be a good feature if there is an option to disable the QR-Code or hide the QR Code, if TOTP method is enrolled. If a user re-open an enrolled T-OTP over the ...

  • Votes

    5

    Check if firewall ports are open

    We would prefer an Option to check if needed Firewall Ports are open. In our opinion this check-up can be located in the Management Consol of AAF. Additionally there ...

  • Votes

    5

    Using the Smartphone app push notification to Accept/Decline ...

    During enrollment, we don't have a notification of the enrollment process that is acknowledged by the user being enrolled. So far the methods we have assume that the ...

  • Votes

    5

    Support for Configuring SMS Sender Policy Using a JSON Body or CURL ...

    Currently when configuring the SMS Sender policy we only support submitting parameters in the http request URL. I was working with a customer that uses Avaya as their ...

  • Votes

    5

    Disable/remove save button when (smartphone) method is enrolled, ...

    The save button is confusing for users if the method is already enrolled. Deleting an re-adding the method is easier to explain to users, especially if "Enroll TOTP ...

  • Votes

    5

    Help Desk "Change User"

    Currently need to click on 'username' to get to 'change user'. Not as intuitive for new users. Can it be a separate button on top to click?

  • Votes

    5

    Define authentication levels for each individual chain

    We have an enterprise access management/SSO application (ForgeRock OpenAM) used to protect web applications. We are looking to integrate Advanced Authentication with it ...

  • Votes

    5

    Brute force / BOT Attack and Data leakage Prevention

    A change in authentication flow can help prevent brute force bot attacks: 1. Information leakage - valid usernames & passwords discovery 2. User lockout due to bad ...

  • Votes

    5

    AA should have a well-thought out configuration option for explicitly ...

    AA should have a well-thought out configuration option for explicitly designated AA Webserver role servers to turn off access to all portals ...

  • Votes

    5

    Improve Client Log rotation

    Please improve the client log rolling The debugging of a sporadically issue is very worse if the logging is running several days/weeks. Today for the naming of the log ...

  • Votes

    5

    Temporarily block user account after x failed attempts – when endpoint ...

    Feature: Being able to configure the system to temporarily block user account after x failed attempts (for instance account could be blocked for 30mn after 5 failed ...

  • Votes

    5

    Ability to authenticate trough RADIUS if LDAP Passwor dis expired

    Please provide an option to allow authentication trough RADIUS if LDAP Password is expired. Today: It is not possible to authenticate trough the radius event with a ...

  • Planned

    5

    AAF smartphone app should allow you to copy the TOTP enrollments

    AAF smartphone app should allow you to copy the TOTP enrollments