• Planned

    9

    Allow enroll admins the ability to unlock user accounts

    When a user is locked out according to the Lockout policy, it would be desirable for someone with enroll admin role to be able to unlock a user. Typically unlocking users ...

  • Votes

    7

    Validate correct password when saving repository settings

    Every time you adjust the settings of a repository, you are required to provide a password for the user you are connecting as however there is no check to see if the ...

  • Votes

    6

    Regenerate endpoint id and secret without having to delete and ...

    It would be convinenet to be able to regenerate an Endpoint's id and secret instead of the current process of having to delete the endpoint and re-creating it. When ...

  • Votes

    5

    Different set of security questions for different groups of users

    Currently when defining security questions, we define a set of questions applicable for the entire AA instance. It is desirable to have different sets of security ...

  • Votes

    4

    Configurable clean up limit to prevent the mass deletion of users as a ...

    Repositories will do a periodic sync. A user is deleted from an AA repository if they are not returned in the result set of a repository sync. Deleting a user from AA is ...

  • Votes

    3

    Configurable grace period before a user is deleted from AA due to not ...

    Repositories will do a periodic sync. A user is deleted from an AA repository if they are not returned in the result set of a repository sync. Deleting a user from AA is ...

  • Votes

    5

    Ability to rename Interface field names (Especially the Interfaces ...

    I have a customer that rolled out AAF for enterprise users with SMS and TOTP as their authentication mechanisms. On roll out they noticed that helpdesk started receiving ...

  • Votes

    6

    Configuration of Windows Client through command line arguments at ...

    The Windows Client must be configured/customized post installation through the config.properties file. For options where it makes sense, it would be beneficial to ...

  • Votes

    4

    Automatic linking of authenticators to like users

    This can be done in the Helpdesk portal but it would be nice to have the automatic linking of authenticators to like users. The criteria by which to define 'like users' ...

  • Votes

    9

    Audit logging of configuration changes

    It would be beneficial to have an audit log of configuration changes (repositories, methods, chains, events, endpoints, etc.) to have some accountability and for ...

  • Votes

    2

    Policy for Help desk Emergency Password.

    Have a Policy that will limit time of how long an Emergency Password can be set for or used. Currently you can create for many years. Max age of Emergency Password ...

  • Planned

    8

    Smartphone Enrollment - Provide ways to seed Username and Description

    When user scans the QR they are prompted to enter username and description. Would like ability to customize where you use: Username: %REPO%\%USERNAME% Description: ...

  • Votes

    2

    Use Case: Workers will be on a ship or out of office for 1 – 6 months, ...

    We have this for NSL and would like to see same option for AA cached credentials

  • Votes

    1

    QR code generator

    Automatically generate QR for manually write seed/secret. After refresh page or immediately when written in box. Or add section to web management with this functionality. ...

  • Votes

    3

    Only Allow Simple Chain On Same Workstation Where High Security Chain ...

    Add a feature that stops user based simple chain use. Normally if a use authenticates using a high security chain they are able to then use the simple chain on any ...

  • Votes

    3

    Disallow modifications to the SMS OTP authenticator method from end ...

    There is no ability to disable modifications made to the SMS OTP Authenticator via the end user portal. The end user is now able to edit the default cell phone number ...

  • Votes

    3

    Disallow modifications to the Email OTP authenticator method from end ...

    There is no ability to disable modifications made to the Email OTP Authenticator via the end user portal. The end user is now able to edit the default email address for ...

  • Votes

    4

    PIN complexity requirements policy

    There is a 'Rename to PIN' functionality in the 'Password' method. I observed that the complexity requirements policy - in this method - does not reflect this. For ...

  • Votes

    4

    OTP Message should include a variable with the timestamp of the OTP

    On version 5.6U1 the SMS OTP method allows for specific variables to be added as part of the message to be sent to the user. At the moment, only 4 variables are available ...

  • Votes

    3

    configurable methods or adding custom methods with different ...

    We want through the methods settings yesterday and when looking into the fingerprint options there was a threshold value to be adjusted. Some other adjustments in other ...