- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Protecting the Authenticate tokencode in the Authenticate app
Hi all,
Our managers want to avoid the scenario where users don't configure automatic lock of their mobile phones. They are worried about users leaving unprotected phones with the Authenticate app open and showing tokencodes.
I've been trying the option "Require PIN or Device Biometrics to view the Authenticate Tokencodehttps://access-eu.securid.com/AdminInterface/customer/281/" in the configuration and it works but... for the first time only. You open the app and are required to write a PIN or use the device biometrics to see the tokencode. But once you've done that, the app continues showing tokencodes, when I was expecting it to lock again when the tokencode shown expires. Is this the expected behaviour?
The other option would be to remove altogether the option to authenticate with tokencodes, but as far as I know is the authentication method needed for first time users, to be able to create a PIN for the Approve method. Is that right?
Thanks
- Tags:
- App
- CAS
- Cloud
- Cloud Auth
- Cloud Authentication
- Cloud Authentication Service
- Community Thread
- Discussion
- Forum Thread
- RSA SecurID
- RSA SecurID Access
- SaaS
- SecurID
- tokencodes
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jose - if you navigate to another app or lock your screen you are forced to re-enter PIN or do biometrics again to see the tokencode. Otherwise, if I turn off my screen lock and leave the application open showing tokencodes they require PIN or biometric again in less than 5 minutes.
Hope that helps,
Ted
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jose - if you navigate to another app or lock your screen you are forced to re-enter PIN or do biometrics again to see the tokencode. Otherwise, if I turn off my screen lock and leave the application open showing tokencodes they require PIN or biometric again in less than 5 minutes.
Hope that helps,
Ted
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Ted! We'll show the available options to management for them to decide
