Skip to main content

Manage assigned smart credentials

After you add a mobile smart credential to a user, you can manage its lifecycle in IDaaS. This includes enabling, disabling, unassigning, unblocking, updating, and deleting assigned mobile smart credentials.

Enable or disable a mobile smart credential

You can enable or disable an Active mobile smart credential.

  1. Click > Members > Users. The Users List page appears.
  2. Click the user ID. The User Details page appears.
  3. Click the Authenticators tab. The Authenticators page appears.
  4. Click for the mobile smart credential that you want to enable or disable. A drop-down list appears.
  5. Click Disable or Enable, as required.
  6. Click Confirm on the confirmation prompt.

Unassign a mobile smart credential

When a mobile smart credential is activated in IDaaS, it is associated with an identity in the user's Mobile Smart Credential application. Unassigning the credential breaks that association so the credential can be activated again on a different device.

  1. Click > Members > Users. The Users List page appears.
  2. Click the user ID. The User Details page appears.
  3. Click the Authenticators tab. The Authenticators page appears.
  4. Click for the mobile smart credential that you want to unassign. A drop-down list appears.
  5. Click Unassign. A pop-up window appears.
  6. Click Unassign. The mobile smart credential is now in the Enrolled state.

    A new user can now activate the unassigned mobile smart credential using the link or a QR code.

Unblock a mobile smart credential

A smart credential becomes blocked when an incorrect PIN is entered too many times in response to a mobile smart credential authentication challenge. The Unblock feature allows you to unlock a mobile smart credential.

  1. Click > Members > Users. The Users List page appears.
  2. Click the user ID. The User Details page appears.
  3. Click the Authenticators tab. The Authenticators page appears.
  4. Click to the right of the Smart Credential - PIV that you want to unblock. A drop-down list appears.
  5. Click Unblock. An Unblock Smart Credential pop-up window appears.
note

See the IDaaS User Online Help for more information on activating a mobile smart credential authenticator.

Update a mobile smart credential

If certificate authorities (CAs) or smart credential definitions have changed or expired, use Update to refresh the mobile smart credential. The credential must be in the Active state. Update is available only when the CA or smart credential definition has changed. The user must have an email address.

  1. Click > Members > Users. The Users List page appears.
  2. Click the user ID. The User Details page appears.
  3. Click the Authenticators tab. The Authenticators page appears.
  4. Click for the mobile smart credential you want to update. A drop-down list appears.
  5. Click Update. An Activate dialog box appears.
  6. Click Activate.

Delete a mobile smart credential

You can delete a mobile smart credential assigned to a user.

  1. Click > Members > Users. The Users List page appears.
  2. Click the user ID. The User Details page appears.
  3. Click the Authenticators tab. The Authenticators page appears.
  4. Click to the right of the Smart Credential - PIV that you want to delete. A drop-down list appears.
  5. Click Delete. A confirmation prompt appears.
  6. Click Delete.

Validate your changes

After you perform one of these actions, confirm the expected result.

  1. Enable or disable: Verify the credential state updates correctly.
  2. Unassign: Verify the credential returns to Enrolled and can be activated again.
  3. Unblock: Verify the user can complete authentication again.
  4. Update: Verify the credential update is sent successfully and completed by the user.
  5. Delete: Verify the credential no longer appears in the user's authenticator list.