• Planned

    6

    search field for locked user for the helpdesk portal / ability to ...

    It would be a good to add these two features. 1) Add search field to search for users in the locked users-list 2) If a user will be opened in the help desk (where you can ...

  • Votes

    5

    Option to hide QR Code in TOTP enrollment

    It would be a good feature if there is an option to disable the QR-Code or hide the QR Code, if TOTP method is enrolled. If a user re-open an enrolled T-OTP over the ...

  • Votes

    3

    NAAF Client 5.6 should get the language for a parameter that it can be ...

    NAAF Client 5.6 should get the language for a parameter that it can be changed by the end user. In our case the system locale can only be changed by the administrator and ...

  • Votes

    2

    When chains are created and user enrolls force that the chain must ...

    While on POC customer enrolled Bluetooth and Proxcard. They then logged out and only had LDAP Password. They were surprised and asked if when they are chained like this ...

  • Votes

    2

    Once a user has enrolled methods provide option to turn off LDAP ...

    On a customer POC and they have Bluetooth and PIN as well as Proxcard and PIN enrolled however they still see LDAP Password as a method when logging into Desktop. They ...

  • Votes

    12

    MFA Smartphone native NetIQ App avoid additonal info after QR code ...

    - Customer uses AAF Version: 5.6 and Access Manager 4.4. - Using the current version, an additonal info entry is offered after the scan of the QR code for an ...

  • Planned

    14

    Periodically export database backup to network location

    Right now you can manually export the database backup and then download it to your local machine. In the future, it is desirable that the database would automatically ...

  • Votes

    8

    Customize RADIUS Reply-Messages per method in a chain

    Applications that correctly implement RADIUS will show the Reply-Message value sent from the AAF server when authenticating with a chain. Right now, the Reply-Message ...

  • Votes

    5

    Allow IP address in multiple RADIUS events

    We are leveraging the NAS Identifier in that each of our RADIUS configurations have an Event for each chain. This enables us to provide our users a clever way to select ...

  • Planned

    4

    Configurable RADIUS auto-enrollment behavior

    Current status: When the RADIUS method is configured with a Radius client, a user is auto-enrolled in the RADIUS method no matter if they have an account in the ...

  • Votes

    4

    Search for tokens

    In an environment where there are a bunch of tokens, the pagination makes it tough to find a specific token. You need to search each page and you can easily need to ...

  • Votes

    4

    Configure appliance proxy settings through Configuration portal

    It would be convenient to be able to set the proxy settings in the Configuration portal of the appliance versus having to do it through yast.

  • Votes

    8

    Use SSL for AD repository DNS discovery

    When using DNS discovery for AD repositories, there should be an option to add them as SSL-enabled on port 636. Today when using DNS discovery for AD repositories, they ...

  • Votes

    3

    Configure endpoint whitlist based on ad group

    We would like the ability to configure endpoints whitlist based on ad/eDirectory group, not by specifying the endpoints directly.

  • Planned

    5

    Add more than one bluetooth authenticator device

    Customer ask for ability to configure more than one bluetooth device as an authenticator. For example, to use either smart watch or smartphone.

  • Planned

    6

    Forward other logs besides Syslog

    We would like to be able to forward more than just the 'Syslog' log to a syslog server. We find the other logs having valuable information and being able to forward all ...

  • Votes

    5

    pin expiry reminder

    Could you add a reminder on login if a PIN is about to expire soon? Ideally I can configure how many days before expiry the reminder comes up.

  • Votes

    8

    1:n matching for Fingerprint

    Requested by: several customers Currently 1:n matching is supported for the card and PKI methods. Our customers also want this for fingerprint authentication as well.

  • Votes

    6

    Provide a country code dropdown when enrolling in SMS OTP

    The user should be provided a dropdown box with a list of country codes that they must select before they can save their phone number for the SMS OTP. This forces their ...

  • Votes

    5

    Define authentication levels for each individual chain

    We have an enterprise access management/SSO application (ForgeRock OpenAM) used to protect web applications. We are looking to integrate Advanced Authentication with it ...