Configuring Authentication Methods in User Policies

The Authentication tab of a user policy controls the authentication methods and options (authentication rules) that define authentication behavior for Enterprise Access Management. User policies also work in conjunction with the Enterprise Access Management for MFA workflow policy to control which workflows users in the policy have access to, in addition to the authentication methods they are allowed to use in those workflows.

The available authentication methods for SSO are detailed in Enterprise Access Management SSO Authentication Methods.

The available authentication methods for MFA are detailed in Enterprise Access Management for MFA Authentication Methods.

Some authentication methods offer additional choices:

NOTE: These limitations do not apply to remote authentication through a VPN connection.

Configuring Licensed Options

The following additional licensed features are enabled in the Licensed options section of the Authentication tab:

  • Fingerprint Authentication (Imprivata Enterprise Access Management for SSO only)

  • Imprivata ID - Hands Free Authentication (Imprivata Enterprise Access Management for MFA only)

  • VASCO OTP Token Authentication

  • Symantec VIP Credential Authentication (Imprivata Enterprise Access Management for MFA only)

Users in the user policy cannot use these licensed features unless they are enabled on the Authentication tab. When you enable one of these features, each user in the user policy counts toward the usage total for that license. See Imprivata Licensed Features.

Enabling Imprivata Enterprise Access Management for MFA Authentication Methods

For information on enabling Imprivata Enterprise Access Management for MFA authentication methods, see Enabling and Configuring Authentication Methods for Imprivata Enterprise Access Management for MFA. Also see Configuring the Enterprise Access Management Workflow Policy.

Two-Factor Authentication

For a table of two-factor authentication methods supported for MFA, see Enterprise Access Management for MFA Authentication Methods.

User Lockout Policy

This setting applies to:

  • Password Authentication

  • Non-password authentication. For example, fingerprint or token

  • Security questions (emergency access)

  • Self-service password reset

NOTE: If the policy is configured for both self-service password reset and authentication through security questions (emergency access), be sure that the settings meet your needs for both emergency access and self-service password reset.

After a number of consecutive authentication failures, the user account is locked. Even if the user authenticates correctly during the lockout period, the account remains locked.

To configure the lockout rules:

  1. In the Imprivata Admin Console, go to Users > User Policies and select a user policy.

  2. Go to the Lockout section at the bottom of the page.

  3. Change the default settings if needed:

  4. Lock user account after 5 consecutive failures within 5 minutes
  5. Lock account for 5 minutes
  6. Click Save.

To create a Primary Lockout event notification, see Configuring Event Notifications.

You can define how many times a user can unsuccessfully authenticate with their finger before the attempts are counted as a "failure." See Fingerprint Authentication Attempts Before Failure.

If your enterprise has the Fingerprint Identification licensed feature, you can suspend fingerprint identification in computer policy after a number of consecutive failures. See Setting Fingerprint Identification Parameters in a Computer Policy.

Authentication Method Options

Specific settings and options for authentication methods are configured in the Authentication method options section of a user policy's Authentication tab.