Modify grid card authenticator settings
Use this procedure to update grid card settings for your account. These settings apply to all grid cards assigned to users. An IDaaS account can include up to 5,000 unassigned grid cards.
Before you change these values, decide how much challenge complexity your users can tolerate. Larger grids, longer challenges, and stricter delivery controls can improve security, but they also make recovery, support, and day-to-day sign-in more difficult for users. If you are unsure where to start, make one change at a time and test it with a small user group before applying it broadly.
The challenge size cannot exceed the total number of cells in the grid, which is the number of rows multiplied by the number of columns. If you change the grid dimensions, review the challenge size and the grid card lifetime together so the settings remain practical for your users.
Modify grid card settings
-
Click > Policies > Authenticators. The Authenticators page appears.
-
Select Grid Card. The Grid Card settings appears.
-
Set the Number of rows for the grid card. Together, the number of rows and columns determines how many cell value combinations are possible.
-
Set the Number of columns for the grid card. Together, the number of rows and columns determines how many cell value combinations are possible.
-
Set the Number of characters per cell to the number of values to include in the grid card cell.
-
In the Cell alphabet field, enter the numbers and letters that can be included in a grid card cell.
-
Select Case Sensitive to make the values entered in the alphabet case-sensitive. When not selected, the Cell alphabet must contain either upper or lowercase letters but not both.
-
Select Include Grid Expiry in Challenge to display the grid expiry date on the grid challenge screen.
-
Select Replace Similar Characters if you want to replace similar looking characters in a response. For example, replace O with
0and I with1. -
Set the Challenge Size to the number of cells your application presents to users during a grid challenge.
- Each cell can contain one or more characters.
- The default setting minimizes the grid card data that is potentially exposed at each login.
- The minimum setting is
1. - The maximum is the total number of cells in the grid (number of rows multiplied by the number of columns).
-
Select Sort Challenge to sort a grid challenge by column and row after generating the challenge. The default enhances usability by presenting cells in order such that the grid card is read from left to right.
-
Select Retain Challenge to retain the challenge for the duration of the Card Challenge Lifetime (secs.). Users who answer a challenge incorrectly will have the same challenge presented to them for all subsequent attempts until they are locked out or until the Challenge Lifetime is exceeded. After the challenge lifetime is exceeded, a new challenge is presented.
-
Set the Challenge Lifetime (secs.) in seconds. A value of
0sets an unlimited lifetime. If the challenge is not answered within the lifetime, a new challenge is generated. -
Set the Grid Card Lifetime (secs.) to the number of days a grid card is valid after it is activated. A value of
0(unlimited) sets that the grid card does not expire based on time. -
Select Encrypt Emails to encrypt the grid card email. Users will need to provide a password to access the encrypted grid card.
-
Select the eGrid Card Page Size.
-
Select the Export eGrid Page Size.
-
Select eGrid Card Attributes included in the grid card export. This information appears on the exported grid card.
-
Select Automatically Email New Grid Cards to automatically email grid cards to users when they have been created or assigned.
-
Select Allow Any Email Attribute for Delivery to allow any email address attribute in the user profile to receive the grid card. If you do not select this option, you must also complete the following:
-
Under Grid Card Delivery Allowlist, select the email attributes that can receive the grid card.
-
Select Deliver Grid Cards to User-Defined Attributes to allow grid card delivery to user-defined email attributes.
-
Deselect Restrict Administrator Roles to Grid Card Delivery Allowlist to allow administrators to select any email address associated with a user for grid card delivery.
noteIf you leave Restrict Administrator Roles to Grid Card Delivery Allowlist enabled, end users and administrator roles can only select email attributes enabled under the Grid Card Delivery Allowlist and the Deliver Grid Cards to User-Defined Attributes.
-
-
If you see a warning message, select Confirm Changes.
-
Click Save to confirm your changes.
Validate your changes
After you save, verify the following:
- A test user can complete a grid challenge with the updated layout.
- The configured challenge size and challenge lifetime behave as expected.
- Delivery and export settings produce the expected format.