POLICIES – Virtual DIGIPASS (tab)
The POLICIES > Virtual DIGIPASS tab shows the Virtual Mobile Authenticator settings of the policy.
Field name | Description |
---|---|
Virtual DIGIPASS | |
Challenge Message |
The challenge message displayed to the user, when performing a Virtual Mobile Authenticator authentication. Note that the templates for other notifications sent by Message Delivery Component (MDC) during Virtual Mobile Authenticator authentication are configured via the global server configuration (see Global Configuration – Virtual DIGIPASS (tab)). Default value (Base Policy): "Enter One-Time Password" |
Delivery Method |
The method used to deliver the Virtual Mobile Authenticator. Possible values:
This field also allows you to specify one of the following combinations of delivery methods:
|
MDC Profile |
The MDC profile to use for this delivery method. It defines a specific group of settings for a particular delivery method. If no MDC profile is specified in this field, the highest-ranked, enabled, and available MDC profile for the specified delivery method/s will be used. The MDC profile name should not be confused with the profile's display name. The display name is simply an ad-hoc field used primarily to describe and further identify the profile. The MDC profile name is the name that appears in the Profile column of the MDC Configuration Utility. The MDC profile name is not unique, therefore, more than one MDC profile with the same name may exist for this delivery method. In that case, the highest-ranked, enabled, and available MDC profile with the specified name will be used. |
Primary Virtual DIGIPASS | |
Request Method |
The method by which a user has to request a Virtual Mobile Authenticator login. The request is made in the password field during login. The request will be ignored if the user does not have a Virtual Mobile Authenticator assigned. Possible values:
|
Request Keyword |
Defines the request keyword that a user must enter to request a primary Virtual Mobile Authenticator login. This applies if a method using a keyword is selected in Request Method. This can be blank. |
Backup Virtual DIGIPASS | |
BVDP Mode |
Specifies whether and how the backup Virtual Mobile Authenticator feature can be used when this policy is effective. Note that for the backup Virtual Mobile Authenticator feature to work, it must also be activated in the DPX file for the authenticator. Possible values:
|
Time Limit (days) |
When the BVDP Mode setting is Yes – Time Limited, the time limit setting indicates the number of days for which the backup Virtual Mobile Authenticator feature can be used by users, once they start to use it. The Backup Virtual DIGIPASS Enabled Until value in the authenticator record will be set automatically the first time that the user requests an authenticator OTP, using the time limit defined in the policy. Once this date has expired, it requires administrator intervention either to extend it or to reset it to blank for the next time that the user needs to use a backup Virtual Mobile Authenticator. Note that if a user has more than one authenticator capable of backup Virtual Mobile Authenticator, each authenticator has a separate limit. |
Max Uses/User |
The maximum number of uses of the backup Virtual Mobile Authenticator feature permitted for each user, if the user does not have a specific limit set for the authenticators. If the Backup Virtual DIGIPASS Uses Remaining value in the authenticator record is blank and there is a maximum uses/user limit defined in the policy, the remaining uses will be set automatically the first time that the user requests a backup Virtual Mobile Authenticator OTP. Once the Backup Virtual DIGIPASS Uses Remaining value has reached zero, backup Virtual Mobile Authenticator can no longer be used with the authenticator, unless the administrator increases it or resets it to blank. Note that if a user has more than one authenticator capable of backup Virtual Mobile Authenticator, each authenticator has a separate limit. |
Request Method |
The method by which a user has to request a backup Virtual Mobile Authenticator login. The request is made in the password field during login. The request will be ignored if the user does not have an authenticator assigned that is activated for the backup Virtual Mobile Authenticator feature, or if any other policy or authenticator settings do not permit backup Virtual Mobile Authenticator use. Possible values:
|
Request Keyword |
Defines the keyword that a user must enter to request a backup Virtual Mobile Authenticator logon if a method using a keyword is selected in Request Method. This can be blank. |
Virtual Signature | |
Virtual Signature Mode |
Specifies whether or not to allow the use of virtual signatures.
|
Delivery Method |
The method used to deliver the virtual signature. Possible values:
This field also allows you to specify one of the following combinations of delivery methods:
|
MDC Profile |
The MDC profile to use for this delivery method. It defines a specific group of settings for a particular delivery method. If no MDC profile is specified in this field, the highest-ranked, enabled, and available MDC profile for the specified delivery method/s will be used. The MDC profile name should not be confused with the profile's display name. The display name is simply an ad-hoc field used primarily to describe and further identify the profile. The MDC profile name is the name that appears in the Profile column of the MDC Configuration Utility. The MDC profile name is not unique, therefore, more than one MDC profile with the same name may exist for this delivery method. In that case, the highest-ranked, enabled, and available MDC profile with the specified name will be used. |