• Votes

    1

    Syslog message when user account is locked by AAF application

    It would be beneficial to have a syslog event generated when a user account is locked by AAF using the Lockout Policy. We created a Lockout Policy designed to lock a ...

  • Votes

    2

    AA Windows Client needs to filter Chains based on hardware that AA ...

    The AA Windows Client needs to filter available Chains list based on the availability of locally present hardware that the AA Device Service detects as available. Right ...

  • Votes

    2

    poorly worded and inappropriate guidance on the SMS and Voice OTP ...

    Need the ability to edit the poorly worded and inappropriate guidance on the SMS OTP and Voice OTP enrollment screens (see screenshots below)? I don’t see a “Policies à ...

  • Votes

    2

    SMS/Voice methods allow for no-confirmation-required abuse when ...

    Security vulnerability: the SMS and Voice methods allow for no-confirmation-required abuse when “registering” phone numbers via the Authenticators Management portal. Just ...

  • Votes

    4

    SMS OTP and Mail OTP: Force number/mail validation during Save

    We would like to be able to force user to verify his email address / mobile number when they are adding/modofying manually an SMS OTP / Mail OTP method from ...

  • Votes

    2

    Change Keyboard Selection at NetIQ Client

    We have Windows systems in all regions of the world and often times are logging into systems in regions outside our working location. This means we are often challenged ...

  • Votes

    2

    Disabling User Report Tab in Helpdesk

    Hello, we noticed that the Tab "User Report" was introduced to the Helpdesk in a newer version. We are not allowed to grant our Helpdesk Admins the possibility to track ...

  • Votes

    2

    SMS OTP request should allow to have a variable which have request ID ...

    This is something similar to the idea 'OTP Message should include a variable with the timestamp of the OTP' but instead timestamp a additional variable that allows to ...

  • Votes

    3

    REST-API Allow other authentication methods for "Destroy endpount"

    Today it is only possible to use PASSWORD:1 for Destroy Endpoint. We would like to have the ability to use other Methods like, LDAP_PASSWORD:1, TOTP:1, HOTP:1 etc.

  • Votes

    5

    Check if firewall ports are open

    We would prefer an Option to check if needed Firewall Ports are open. In our opinion this check-up can be located in the Management Consol of AAF. Additionally there ...

  • Votes

    1

    Enable user exception group list in Geo-Fencing

    For example for “Singapore” & “Malaysia” group = user1, user2, user3, but for “China” group = user1 only & user2, user3 is deny access.

  • Votes

    3

    Method: Password Policy

    An Option to set different Password Policy for each user Group, if the Password set as a chain from MFA such as Pin + OTP. We want able to set for the UserGroups a Simple ...

  • Votes

    3

    messagebird

    The AAF 6.2 product contains an SMS TOTP method preconfigured for MessageBird. Which is great. However, the method uses the "OLD HTTP-API_v1" as MessageBird refers to ...

  • Votes

    4

    Don't include Smartphone enrollments as part of backed up app data for ...

    This behavior was observed when a user migrated from an older iPhone to a new iPhone but may also apply to Android devices. Current situation: The Smartphone enrollments ...

  • Votes

    3

    Allow multifactor when enrolling smartphone via /smartphone/enroll url ...

    As an Administrator of AAf, admin should be able to add MFA for direct smartphone enrollment url as well. Currently, the product (AAf 6.2) support direct smartphone ...

  • Votes

    1

    Retrieve and accept user names in different format

    Some applications/systems use naming schema different then simple username. Good example might be FUDO running in "bastion" mode. In that case username consists of two ...

  • Votes

    2

    Radius only return the CN from the group name

    Some customers have trouble with specific VPN Solutions from Cisco or Watchguard. Because with this tools it seems that there is a limitation for the group name field (as ...

  • Votes

    5

    Support for Configuring SMS Sender Policy Using a JSON Body or CURL ...

    Currently when configuring the SMS Sender policy we only support submitting parameters in the http request URL. I was working with a customer that uses Avaya as their ...

  • Votes

    2

    Offline mode: Allow computer to fail open

    Currently: If a user is offline, and if he has lost/broken one authenticator (if 2FA deployed with 'something you know' + 'something you have'), he can't login to his ...

  • Votes

    7

    Deleting a Smartphone authenticator in the NetIQ app deletes the ...

    Current situation: If you delete a Smartphone authenticator from the Self-Service portal/server-side, the Smartphone authenticator on your NetIQ app is deleted. However, ...