Modify hardware token settings
Use this page to configure policy values for standard hardware token authentication. These settings affect how long token responses remain valid and how much variation is allowed during authentication and reset operations.
Modify hardware token settings in IDaaS
Before you make large changes, test with a small user group. If the allowed time is too short, more users can fail sign-in. If the allowed time is too long, security risk can increase.
-
Click > Policies > Authenticators. The Authenticators page appears.
-
Select the Hardware Token tab. The Hardware Token settings appear.
-
Set the Max. Time Steps to the amount of time (in
30second intervals) that the token response is valid. The default is10(5minutes). -
Set the Max. Reset Time Steps to the amount of time (in
30second intervals) for a token reset. The default is120(60minutes), which is the allowable time difference between the token and the server clocks. -
For event-based tokens (HOTP tokens), configure the following settings:
-
Set Max Event Window to the numbers of token responses that are searched to find a matching user response during authentication.
The value entered must be less than the Max Reset Event Window. The value must be between
1and25. The default value is10. -
Set Max Reset Event Window to the number of token responses that are searched to find a matching user response during a token reset operation. The value must be between
1and100. The default value is80.noteIf the token reset does not work, depending on the type of token you are using, try increasing the Max. Reset Time Steps or Max. Reset Event Window and then try to reset the token again. If the problem continues, call the Entrust customer support team.
-
Click Save to confirm changes to your Hardware Token authenticator settings.
Validate your changes
After you save, verify the following:
- A test user can complete normal token authentication with the configured Max. Time Steps and Max Event Window values.
- Token reset succeeds with the configured Max. Reset Time Steps and Max Reset Event Window values.
- Authentication failure rates do not increase unexpectedly after the policy change.
To use a TokenCR (Token Challenge/Response) hardware token, you additionally need to create a custom user login authentication flow that uses Token/Challenge Response for second-factor authentication. See Create authentication flows.