Configuring Authentication Methods in User Policies
The Authentication tab of a user policy controls the authentication methods and options (authentication rules) that define authentication behavior for Enterprise Access Management.
The available authentication methods for SSO are detailed in Enterprise Access Management SSO Authentication Methods.
The available authentication methods for MFA are detailed in Enterprise Access Management for MFA Authentication Methods.
Some authentication methods offer additional choices:
-
OneSpan OTP (previously VASCO) token users can be authorized for offline authentication, and they can be allowed to self-enroll their OneSpan OTP tokens. See Configuring OneSpan (VASCO) One-Time Password (OTP) Token Options (SSO Only)
-
Users who can authenticate by fingerprint can also enroll additional fingerprints after initial enrollment.
-
Because a user may not get a good fingerprint scan for authentication, you must also enter a maximum value for the number of fingerprint authentication attempts that can fail before the authentication attempt is considered a failure. See Configuring Fingerprint Authentication Options (SSO Only)
NOTE: These limitations do not apply to remote authentication through a VPN connection.
Configuring Licensed Options
The following additional licensed features are enabled in the Licensed options section of the Authentication tab:
-
Fingerprint Authentication (Imprivata Enterprise Access Management for SSO only)
-
Imprivata ID - Hands Free Authentication (Imprivata Enterprise Access Management for MFA only)
-
VASCO OTP Token Authentication
-
Symantec VIP Credential Authentication (Imprivata Enterprise Access Management for MFA only)
Users in the user policy cannot use these licensed features unless they are enabled on the Authentication tab. When you enable one of these features, each user in the user policy counts toward the usage total for that license. See Imprivata Licensed Features.
Enabling Imprivata Enterprise Access Management for MFA Authentication Methods
For information on enabling Imprivata Enterprise Access Management for MFA authentication methods, see Enabling and Configuring Authentication Methods for Imprivata Enterprise Access Management for MFA. Also see Configuring the Enterprise Access Management MFA Workflow Policy.
Two-Factor Authentication
For a table of two-factor authentication methods supported for
User Lockout Policy
-
Password Authentication
-
Non-password authentication. For example, fingerprint or token
-
Security questions (emergency access)
-
Self-service password reset
NOTE: If the policy is configured for both self-service password reset and authentication through security questions (emergency access), be sure that the settings meet your needs for both emergency access and self-service password reset.
After a number of consecutive authentication failures, the user account is locked. Even if the user authenticates correctly during the lockout period, the account remains locked.
To configure the lockout rules:
-
In the Imprivata Admin Console, go to Users > User Policies and select a user policy.
-
Go to the Lockout section at the bottom of the page.
-
Change the default settings if needed:
- Lock user account after 5 consecutive failures within 5 minutes
- Lock account for 5 minutes
-
Click Save.
To create a Primary Lockout event notification, see Configuring Event Notifications.
You can define how many times a user can unsuccessfully authenticate with their finger before the attempts are counted as a "failure." See Fingerprint Authentication Attempts Before Failure.
If your enterprise has the Fingerprint Identification licensed feature, you can suspend fingerprint identification in computer policy after a number of consecutive failures. See Setting Fingerprint Identification Parameters in a Computer Policy.
Authentication Method Options
Specific settings and options for authentication methods are configured in the Authentication method options section of a user policy's Authentication tab.