Skip to main content

Manage authenticators

An authenticator helps protect an application from unauthorized access by requiring users to complete an authentication step, such as a password, OTP, or push approval, during sign-in.

User authenticators

The following points describe how authenticators are assigned in IDaaS:

  • Users can be assigned multiple authenticators.
  • Users must have at least one authenticator to sign in to IDaaS.
  • Users can select OTP delivery by voice, email, or SMS when the corresponding contact details are registered in their profile.
  • Assigned tokens have a state of Active or Inactive. Only Active tokens can be used for authentication.
  • Resource rules determine which authenticators can be used to sign in to an application.
  • Users created locally in IDaaS or synchronized from Active Directory (AD) can be assigned authenticators automatically.
note

This section explains how to configure global settings on the General page and how to configure authenticator policies. To apply different settings for specific groups, use Group policies.

Push transaction queuing

The push transaction queuing feature supports users who need to verify multiple transactions during the day and may need time to complete other steps before confirming each transaction.

For example, bank loan officers can use this feature during the loan approval process. When enabled, IDaaS can send multiple transactions to a user’s mobile soft token app and allow the user to respond within a configured time period.

If the queue size set to 1, only one transaction can be active at a time for a soft token identity. A new transaction overwrites the previous one. Additionally, transactions typically expire after a short time.

Example of queued transactions

A loan officer at AnyBank is asked to approve about 15 loans a day. The approval is granted by responding to a transaction challenge sent to loan officer's mobile soft token identity being used for transaction queuing.

The administrator configured the push transaction to expire after two days (Push Transaction Lifetime). To handle spikes in activity, the administrator also set the Maximum Queued Transactions to twice the typical daily transaction volume. As a result, the loan officer can have up to 30 transactions queued for this identity.

When the queue reaches this limit, the system removes expired transactions first, or deletes the oldest transactions to make room for new ones. Ideally, the queue never reaches this limit, and the loan officer responds to each transaction before the system deletes it.

For more information, see Manage General settings.

Assigning user authenticators

To assign authenticators to users, see the following:

For instructions on how users authenticate with them, see the IDaaS User Online Help.

Topics in this section