Tokens General Information
Tokens are authentication methods used as a second factor in authenticating a user's identity. there are a variety of token types that a user can enroll in, from SMS or email tokens to Google Authenticator tokens, to hardware tokens in the form of cards or tokens. Each user enrols at least one token when registering for the system. Each user must have at least one token active, regardless of its type. Not every function is available for every type of token.
Available actions for users with appropriate privileges:
Register the new token. |
||
Modify user comment (if allowed) or mobile phone number for SMS token or email address for Email token. |
||
Permanently delete a token. |
||
Test a token to verify that it is working correctly. |
||
Reset of a non-synchronous token. |
||
Disable or enable token - disabled token can't be used for verification as a second factor. |
||
[click on the row] |
Display the page with all the details of the specific token. |
The list of available actions for the tokens depends on the type of the token and assigned privileges. For example, an SMS token can't be reset due to its nature, or users from a specific group can't delete the token due to company policy. The configuration is done on the administrator level.
Status of the token:
ACTIVE |
The token is active and ready to be used for user identity verification (in login or approval processes). |
|
DISABLED |
The token is disabled and cannot be used to authenticate the user's identity. |
|
OBSOLETE |
A token is out of date and it needs to be deleted and registered another one. For example, if it is an SMS or EMAIL token, it is possible to delete it and replace it with a so-called Virtual token, which works the same - based on sending an OTP to an email address or mobile phone. |
Adding a new token
Enrollment of the tokens is slightly different from type to type. For detailed instructions visit the page for the specific token: |
Click on the links to see the details of the enrollment of specific tokens. Token-type names are fully adjustable by the administrator, so they could be different from the used samples. |
Modify an existing token
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
|
2 |
Press the EDIT button [ ] within the chosen token from the context menu [ ].
|
|
3 |
A new form with the parameters of the token will be opened. |
|
4 |
Adjust the available parameters and press the SAVE button to save the changes. |
Deleting a token
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
|
2 |
Press the DELETE button [ ] within the chosen token from the context menu [ ] and confirm the removal.
|
|
3 |
If the deletion is possible (and possibly approved) the token is removed from the list of tokens. |
Token test
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
2 |
Press the TEST button [ ] within the chosen token from the context menu [ ]. |
3 |
The application opens a new page for the test of the token. All tokens have their own test procedures: |
5 |
If everything is correct, you will see information about the successful test. |
6 |
If the token test result is negative, you can do any of the following: |
Token reset
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
|
2 |
Press the RESET button [ ] within the chosen token from the context menu [ ]. Note: not all token types allow the reset action to be performed (mainly HOTP types of tokens). |
|
3 |
The token reset form will be opened. |
|
4 |
Generate two consecutive one-time passwords (OTP) from Google authenticator or a HW token key, enter them into the form and press the RESET button. It is necessary to follow the order of entering both OTPs |
|
5 |
If everything is correct, you will see information about the successful reset. |
Disable temporarily / enable token
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
|
2 |
Press the DISABLE TEMPORARILY button [ ] within the chosen token from the context menu [ ] and confirm the disable/enable action Note: a user must always have at least one token in an active state, which means they cannot disable all their tokens. |
|
3 |
The token will be disabled - the status will change to DISABLED - and it won't be possible to authorize this token within the logging or any other operation. |
Display token detail
1 |
Open the Selfservice, go to the Account section and open the Tokens tab. |
|
2 |
Select the desired token and mouse-click on the selected row. |
|
4 |
the drawer with the details of the token will be opened:
|
|
5 |
The drawer also contains buttons for operations available for the token:
|