Test: Online authentication only
When testing online authentication, you can test authentication with a static password or a one-time password (OTP), and re-test the static password by checking the settings in Active Directory Users and Computers Extension.
Test online authentication with a static password
Before you begin
Before running the test, check the record for the Digipass authenticator you want to use for the test. You need to verify that the grace period for the authenticator is set to a time in the future. If this is not the case, the static password logon will fail.
Modify the test policy
To run the test successfully, you need to modify the Test policy created in Create a test policy as outlined in the following procedure.
- Open the OneSpan Authentication Server Administration Web Interface.
- Navigate to Policies > List.
- Select the Test policy.
-
In the Policy tab, set Local Authentication to Digipass/Password during Grace Period.
- Click Save.
- In the User tab, set Password Autolearn to Yes.
- Click Save.
Test logon
Attempt to log on with the test user ID and the static Windows password.
During logon, OneSpan Authentication Server automatically creates a user record for the test user, assigns them a Digipass authenticator, and auto-learns the Windows static password. The grace period (during which a logon with static passwords is still permitted) is started.
The logon should succeed.
Test online authentication with a one-time password
Modify the test policy
To run the test successfully, you need to modify the Test policy created in Create a test policy as outlined in the following procedure.
- Open the OneSpan Authentication Server Administration Web Interface.
- Navigate to Policies > List.
- Select the Test policy.
- In the Digipass tab, set Application Type to Response-Only.
- Click Save.
Test logon
Attempt to log on with the test user ID and the current OTP from the Digipass authenticator assigned to the test user. The logon should succeed.
Re-test the static password
Before you begin
In the Active Directory Users and Computers Extension, check the record for the used Digipass authenticator. The grace period should be set to a time in the past.
Test logon
Attempt a test logon with the test user ID and the static Windows password. The logon should fail.