Authentication Settings (New UI)

The Authentication Settings page provides configuration options for the authentication methods used by VPAM users.

From this page, administrators can define authentication requirements and manage supported authentication methods.

To open the Authentication Settings:

  1. Open System Administration.

  2. Click Authentication Settings.

Authentication Requirements

Authentication Requirements allows a VPAM administrator to configure the multi-factor authentication (MFA) methods that users must use to access VPAM.

NOTE:

The settings in this page apply to internal users.

TIP:

These same Authentication Requirements are configured on a per-Vendor basis on each Vendor page.

To open the Authentication Requirements page, go to System Administration > Authentication Settings > Authentication Requirements.

Authorized Networks

Authorized Networks define approved IP addresses or CIDR ranges from which Internal Users are permitted to access the VPAM server. This means that your Internal User must connect from an authorized source IP address before they can authenticate.

When a login attempt occurs, the VPAM server evaluates the source IP address:

  • If the source IP address matches a configured Authorized Network, authentication proceeds normally.

  • If the source IP address does not match an authorized network, the login attempt is denied.

Authorized Networks provide an additional layer of access control by restricting where Internal Users can connect from before authentication is completed. They are configured at the server level as part of the server's authentication requirements.

You can configure a single IP address (for example, 192.168.10.15) or a CIDR network range (for example, 192.168.10.0/24).

Risk-Based Authentication

IMPORTANT:

This feature requires the Identity Assurance and Threat Detection (IATD) package. This package includes Facial Biometric Authentication and Identity Threat Detection and Response (ITDR). Contact your Imprivata Customer Success Manager or call +1 800 935 5958 to activate this feature.

When enabled, Risk-Based Authentication (RBA) automatically detect and take action against unusual login behavior. This additional layer of protection improves security without adding friction to trusted users.

For more information, see Configure Risk-Based Authentication.

Nexus Authentication Requirements

Nexus Authentication Requirements enables you to enforce Imprivata VPAM to validate that Multi-Factor Authentication (MFA) was met by Nexus Vendor Reps in their home CPAM server.

CAUTION:

When you select and save Require Multi-Factor Authentication from users, the change immediately requires all Nexus Vendor Reps to have met their home CPAM server's MFA Requirements. If your Vendor Reps have not already configured MFA in a way that Imprivata can validate that MFA is happening, the system will block their connection through the Nexus.
It is recommended that you communicate and schedule the MFA enforcement prior to making this change. Ensure that you share the Multi-Factor Authentication (MFA) Validation for Nexus Connections document to your Vendors before enforcing MFA.