Modify Entrust Soft Token authenticator settings
Review the Entrust Soft Token authenticator settings, and edit them as required. Changes made to these settings apply to all assigned Entrust Soft Tokens in your account.
Modify an Entrust ST Authenticator
-
Click > Policies > Authenticators. The Authenticators page appears.
-
Select Entrust Soft Token. The Entrust Soft Token settings page appears.
-
Select the OTP Digit Length. This sets the number of digits in the OTP generated by the token.
-
By default, Application Launch Scheme is set to
igmobileotp. Change this value only if you use a custom mobile application. -
Optional: Select PIN Required if you want users to enter a PIN.
-
Set the Max. Time Steps to the amount of time (in
30second intervals) that the token response is valid. The default is10(5minutes). -
Set the Max. Reset Time Steps to the amount of time (in
30second intervals) for a token reset. The default is120(60minutes), which is the allowable time difference between the soft token and the server clocks.noteIf the token reset does not work, try increasing the Max. Time Steps and then try to reset the token again. If the problem continues, contact the Entrust Support Team.
-
Enter the Activation Password Length to set number of characters that can be included in the password assigned to a user.
-
Enter the Activation Lifetime to set the amount of time in seconds that a user has to activate their Entrust ST.
-
Select Allow Unsecure Device to allow the Entrust ST to run on an unsecured device (such as custom ROM Androids or jail-broken iOS devices).
-
Select Allow Device Biometrics Authentication to allow users to unlock the mobile application with biometric authentication instead of the token PIN. If disabled, users must enter their PIN.
-
Select the activation methods to include in the Entrust Soft Token activation email. You must select at least one option.
-
Select Require Device Verification to require users to perform device verification when they activate their mobile soft token on the mobile soft token app. Device verification ensures that the user's device has a trusted device certificate.
-
Select Require App Verification to require users to perform app verification when they activate their mobile soft token on the mobile soft token app. If you select this option, the following additional settings appear:
-
Android Application Package Name
-
IOS Application Bundle ID
-
IOS Team ID
noteYou only need to change these values if your users use a custom mobile identity app. There is no need to change them for the Entrust Identity app. When App verification is enabled, an attestation from Apple or Google is provided that validates the mobile application performing the activation. This feature ensures token activation occurs only from trusted mobile applications.
-
-
Select Enable Mutual Challenge to require users to respond to a mutual push authentication challenge. When enabled, users must match the challenge that appears on the IDaaS page with the mutual challenge shown in their Entrust Identity soft token app.
-
Set the Mutual Challenge Length to the number of characters in the mutual challenge.
-
Set the Mutual Challenge Alphabet to the characters that can appear in the challenge.
-
Set Mutual Challenge for Percent of Requests to the percentage of user challenges that include a mutual challenge.
-
Select Allow Actionable Notifications to allow users to perform actions directly from push notifications. For example, Confirm or Deny access.
notePIN Required must be disabled to use this feature.
-
Click Save to confirm changes.
Validate your changes
After you save, verify the following:
- Updated policy values remain selected after refresh.
- Activation email methods appear as configured.
- Users can complete activation with the required verification settings.
- If enabled, mutual challenge and actionable notifications behave as configured.