Configuring Authentication Methods in User Policies

The Authentication tab of a user policy controls the authentication methods and options (authentication rules) that define authentication behavior for Enterprise Access Management.

The available authentication methods for SSO are detailed in Enterprise Access Management SSO Authentication Methods.

The available authentication methods for MFA are detailed in Enterprise Access Management for MFA Authentication Methods.

Some authentication methods offer additional choices:

NOTE: These limitations do not apply to remote authentication through a VPN connection.

Configuring Licensed Options

The following additional licensed features are enabled in the Licensed options section of the Authentication tab:

  • Fingerprint Authentication (Imprivata Enterprise Access Management for SSO only)

  • VASCO OTP Token Authentication

Users in the user policy cannot use these licensed features unless they are enabled on the Authentication tab. When you enable one of these features, each user in the user policy counts toward the usage total for that license. See Imprivata Licensed Features.

Enabling Imprivata Enterprise Access Management for SSO Desktop Authentication Methods

Imprivata Enterprise Access Management for SSO authentication methods require an Authentication Management license. Each EAM user must have at least one authentication method, and any user can have two or more methods. You can set user policies to require two-factor authentication with some authentication methods, such as fingerprint plus proximity card.

Two-Factor Authentication

For a table of two-factor authentication methods supported for SSO, see Enterprise Access Management SSO Authentication Methods.

User Lockout Policy

This setting applies to:

  • Password Authentication

  • Non-password authentication. For example, fingerprint or token

  • Security questions (emergency access)

  • Self-service password reset

NOTE: If the policy is configured for both self-service password reset and authentication through security questions (emergency access), be sure that the settings meet your needs for both emergency access and self-service password reset.

After a number of consecutive authentication failures, the user account is locked. Even if the user authenticates correctly during the lockout period, the account remains locked.

To configure the lockout rules:

  1. In the Imprivata Admin Console, go to Users > User Policies and select a user policy.

  2. Go to the Lockout section at the bottom of the page.

  3. Change the default settings if needed:

  4. Lock user account after 5 consecutive failures within 5 minutes
  5. Lock account for 5 minutes
  6. Click Save.

To create a Primary Lockout event notification, see Configuring Event Notifications.

You can define how many times a user can unsuccessfully authenticate with their finger before the attempts are counted as a "failure." See Fingerprint Authentication Attempts Before Failure.

If your enterprise has the Fingerprint Identification licensed feature, you can suspend fingerprint identification in computer policy after a number of consecutive failures. See Setting Fingerprint Identification Parameters in a Computer Policy.

Authentication Method Options

Specific settings and options for authentication methods are configured in the Authentication method options section of a user policy's Authentication tab.