Assign hardware tokens
You can assign a hardware token to a user after the token seed file is imported into your IDaaS account. A hardware token can be assigned to only one user at a time, but a user can have multiple hardware tokens. After users are assigned hardware tokens, update your resource rules as required so they can authenticate to their application accounts using hardware tokens. You can assign tokens directly to users, or users can self-assign them after you send the tokens to them.
Before you start, confirm the following:
- The hardware token seed file is already imported.
- The target user account exists and is active.
- The token serial number is available and currently unassigned.
Assign hardware tokens to users
Hardware tokens can be assigned to users as follows:
Assign hardware tokens from the Tokens page
- Click > Resources > Tokens. The Tokens page appears.
- Click Unassigned. The list of unassigned hardware tokens appears.
- Identify the serial number of the token you want to assign to your user. You can use the filter option to search for a token (see Manage hardware tokens for more information on filtering tokens).
- Click for the hardware token you want to assign to a user. The Assign Hardware Token dialog box appears.
- In the User ID field enter the user's IDaaS user ID.
- Click Assign. The user is assigned the token and can now use it to complete second-factor authentication.
- Click Assigned. The token appears in the Assigned list.
After assignment, verify that the token appears in the Assigned list and is linked to the expected user.
Assign hardware tokens from the Authenticators page
- Click > Members > Users. The User List page appears.
- Click the user ID of the user being assigned the hardware token. The User Details page appears.
- Click the Authenticators tab. The user's list of assigned authenticators appears.
- Click . A drop-down list of authenticators appears.
- Select Hardware Token. The Assign Hardware Token dialog box appears.
- In the Token Serial Number field, enter the hardware token serial number.
- Click Assign. The authenticator is assigned to the user.
After assignment, confirm the token appears in the user's Authenticators tab.
Assign hardware tokens in bulk
See Bulk assign authenticators.
User self-assigns hardware token
The administrator can have the user self-assign the hardware token.
Send the hardware token and serial number to the user, then instruct the user to complete self-assignment in the User Portal.
Before you begin, upload the token data file to your IDaaS account. See Import hardware tokens for more information.
Edit group membership
If you need to change the group membership for a hardware token before assigning it to a user, do the following:
- Click > Resources > Tokens. The Tokens page appears.
- Click next to the hardware token. The Edit Token dialog box appears.
- Add or delete groups as required.
- Click Submit.
Validate your changes
After you assign tokens or edit group membership, verify the following:
- The token is assigned to the expected user and no longer appears in the unassigned token list.
- The user can see and use the assigned token for authentication.
- Group membership changes are saved for the selected token.