Axidian Key
Authentication with push notifications has the following requirements:
In the network infrastructure:
- Axidian Key Server is installed. This server sends notifications to the user smartphone through the Google API services.
- Axidian Key authentication provider is installed. Installing the provider allows you to use this authentication technology in the target scenarios.
On the client side:
- The Axidian Key application is installed. The application is required to receive authentication notifications in the target applications through the Axidian Access components.
Authentication with push notifications is impossible without Axidian Key Server, Axidian Key Provider, and the Axidian Key application.
Axidian Key Provider can be used for authentication in the following modules:
- ADFS Extension
- Enterprise SSO
- Identity Provider
- IIS Extension (only in the mode of sending push notifications with sign-in confirmation)
- NPS RADIUS Extension (only in the mode of sending push notifications with sign-in confirmation)
- RDP Windows Logon (only in the mode of sending push notifications with sign-in confirmation)
- Windows Logon
{DEEF0CB8-AD2F-4B89-964A-B6C7ECA80C68}
Install Axidian Key Provider
To install the provider:
Run the installation file located at
Axidian Access <version number>/Axidian Providers/Axidian Key Providerand follow the steps of the installation wizard. Install the provider both on the computer with Core Server installed and on the client computer.ImportantIf several Core Servers are used in your infrastructure, install the provider on all the servers of the infrastructure.
If the provider is used in client scenarios with Windows Logon and ESSO Agent, install the provider from the Client folder on the client machines.
After the installation is complete, a system restart may be required. If the installation wizard prompts you to restart the system, confirm this action.
To remove or restore the product, open the Control panel menu and use the standard procedure for the supported operating systems.
Configure Axidian Key Provider in the Management Console
To configure Axidian Key in the Management Console, go to Configuration → Authenticators and select the Axidian Key authenticator.
Access rights
To grant or revoke the rights to use the authenticator:
- In the General settings section, configure the following:
- In the Forbid to use setting, specify whether the user can use or register the selected authenticator.
- In the Actions available to the user section, configure the following:
- In the Register new authenticators setting, specify whether the user can register new authenticators.
- In the Edit existing authenticators setting, specify whether the user can modify the authenticators that are already registered.
- In the Delete existing authenticators setting, specify whether the user can delete the authenticators that are already registered.
- In the Allow editing the authenticator comment setting, specify when the user can edit the comments of the authenticators that are already registered.
Block the authenticator
To block the authenticator, configure the following in the Authenticator blocking settings section:
- Allow or block the use of Axidian Key in case of a series of failed authentication attempts.
- In the Number of authentication attempts before blocking field, specify how many times the user can fail authentication before the authentication method is blocked.
- In the Blocking counter reset field, specify how many minutes must pass after a failed authentication attempt before the counter is reset.
- In the Timeout before the sign-in method is unblocked field, specify after how many minutes the blocked authentication method becomes available again.
Mobile application settings
To configure the Axidian Key mobile application, configure the following in the Mobile application settings section:
- In the Displayed server name field, specify the name of the Axidian Key server that is displayed in the mobile application.
- In the Push confirmation method setting, select how the user is asked to confirm the sign-in:
- No confirmation required — the user is not asked for additional authentication on the device.
- Confirmation with biometrics — the user is asked for additional authentication on the device with biometrics.
- Confirmation with any method available on the device — the user is asked for additional authentication on the device with any method available on it.
- In the Display the one-time password in the mobile application for new authenticators setting, specify whether the one-time code is displayed in the authenticator card in the application. By default, the one-time code is hidden.
- In the Confirmation method for displaying the OTP setting, select how the user confirms the right to view the one-time codes:
- No confirmation required — the user is not asked for additional authentication on the device.
- Confirmation with biometrics — the user is asked for additional authentication on the device with biometrics.
- Confirmation with any method available on the device — the user is asked for additional authentication on the device with any method available on it.
- In the OTP display time field, specify how long the one-time password remains valid. The value is specified in seconds.
- In the Axidian Key operating mode setting, select the sign-in confirmation method used in the application:
- Push — the user receives push notifications with the option to reject or confirm the sign-in.
- OTP — instead of push notifications, the user receives a one-time code.
Server settings
To configure the server that the Axidian Key application connects to, configure the following in the Server settings section:
- In the Axidian Key Server URL field, specify the address at which the Axidian Key server is available from the Axidian Access machine.
- In the Axidian Key Server trusted ID field, specify an arbitrary unique identifier. This identifier is required to confirm the authenticator deletion. The identifier value must match the value specified in the Axidian Key Server configuration file (the
trustedClientstag).
One-time password settings
To configure the one-time password generation, configure the following in the OTP settings section:
- In the OTP refresh period field, specify how long the one-time password remains valid.
- In the Comparison window setting, specify how many refresh periods must pass before the one-time password is considered invalid.
- In the User name format setting, select the format in which the user name is displayed in the application. The default value is Name.
- In the OTP code generation algorithm setting, select the algorithm used to generate the one-time password.
- In the Number of digits in the OTP code setting, select how many digits the one-time password contains.
Register the Axidian Key authenticator via a link
Registering the Axidian Key authenticator via a link from an email requires the following conditions:
- Email OTP Provider is installed and configured.
- The user email is filled in the Active Directory catalog.
The link is sent to the email address specified for the user in the Active Directory catalog.
To register Axidian Key via a link:
Go to Configuration → Authenticators, and in the Registration settings section, configure the following:
- In the Authenticator registration method setting, select the registration via a link from an email.
- Then specify the following:
- In the Notification subject field, specify the subject of the registration email.
- In the Message field, specify the email body.
- In the Link text field, specify the text of the link that the user follows to register the authenticator.
- If required, specify the server address used to form the link. If you leave the field empty, the default link is used, depending on the Axidian Access locale.
Then go to the Users section, select a user, and open the Authenticators tab.
Click Register and select Axidian Key from the list.
After that, the user receives an email with a link to the authenticator registration. As soon as the email is sent, the Axidian Key authenticator with the Pending status is added in the Management Console and in the User Console. Following the link, the user goes to the Axidian Key application, where the authenticator registration starts.
After the user has completed the registration in the application, the administrator must click the status refresh icon in the Management Console and then click Save. The Pending status changes to Active, and the authenticator is ready to use.
If the user encounters errors during the Axidian Key registration, the Pending status changes to Error after the status is refreshed in the Management Console. Delete the authenticator and repeat the registration procedure.
Register the Axidian Key authenticator with a QR code
To register Axidian Key with a QR code:
- In the Actions available to the user section, allow the user to register new authenticators.
- In the Authenticator registration method setting, select the registration with a QR code.
Axidian Key appears in the list of available authenticators for the user in the User Console.
The user must do the following:
- Click the gear icon.
- Click Register.
- Open the Axidian Key application and click +.
- Scan the QR code that appears.
Configuring the registration link and the Axidian Key download link
The link to the authenticator registration and to the Axidian Key application download can be defined manually. To do this:
- Go to Configuration → Authenticators, to the Registration settings section.
- In the Server address used to form the authenticator registration link (deeplink) setting, specify the registration link that is sent by email.
- In the Additional settings section, specify the link to download Axidian Key.
Spam protection
The spam protection mechanism is based on calculating the percentage of successful authentications relative to all sent messages over a specified time interval. The calculation process starts only if the number of sent messages exceeds the number that you have specified in the Evaluation Window setting.
When a spam attack is detected, further message sending is blocked for a specified period of time, and a "Potential spam attack detected" error occurs when attempting to log in.
Messages can be sent again either after the specified period expires or when a certain percentage of successful authentications is reached.
To configure spam protection, perform the following actions:
- In Management Console, in the Configuration→Authenticators section, select an authenticator.
- In the Spam Protection Settings section, configure the following settings:
- Enable or disable spam protection.
- In the Authentication attempts evaluation window field, specify the time period during which the percentage of successful login attempts is calculated.
- In the Authentication attempts threshold window field, specify how many login attempts must be made during the time specified in the authentication attempts evaluation window.
- In the Percentage of successful authentication attempts field, specify the minimum percentage of successful logins relative to all sent messages.
Example
The setting is enabled with the following values:
- Authentication attempts evaluation window — 600
- Authentication attempts threshold window — 20
- Percentage of successful authentication attempts — 85
Spam protection is activated if 21 login attempts occur (21 messages sent). The authenticator will be blocked for 600 seconds.
The authenticator will be unblocked in one of the following cases:
- the percentage of successful logins (user successfully entered the one-time password from the message) reaches 85;
- 600 seconds have passed since the blocking.
Log server events:
- 2090: Potential spam attack detected. Message sending suspended.
- 1118: Message sending to users resumed.
Configure the trusted identifier for Axidian Key Server
By default, when an authenticator is deleted in the User Console, in the authenticator management tool, or in the administrator console, the authenticator is removed from the system without notifications and continues to be displayed in the application.
To configure push notifications about the authenticator deletion and the deletion in the application:
Open the Axidian Key Server configuration file
Web.configfrom theC:\inetpub\wwwroot\axidiankeyfolder.Add the following tags to the file after the
appSettingsblock:NoteIn the
idparameter of theaddtag, enter the unique identifier specified in the Axidian Key Server trusted ID setting in the Management Console.Example<trustedClientsSettings>
<trustedClients>
<add id="the unique identifier set when configuring Axidian Key Server" />
</trustedClients>
</trustedClientsSettings>After the parameters are applied, the user receives notifications about the key deletion.
Configure the Axidian Key application on a smartphone
The Axidian Key application is available for smartphones with iOS 13.0 and higher, and Android 7.0 and higher.
The Axidian Key application is guaranteed to work correctly only if it is downloaded from the official application stores. To download or update the application, use the following links:
To update the application, download the update from the same store where you installed the previous version.
A note for Android device owners
For push notifications to work correctly on Android devices, make sure that the following mandatory requirements are met:
- You have allowed the application to send notifications.
- On devices with Android 9 and higher, the power saving mode is disabled.
Note: push notifications may not work correctly on all Android modifications.
Open the application. In the Authenticators panel, click + to add an authenticator.
Allow the application to access the camera and scan the QR code.
Confirm the authenticator registration by clicking Confirm.
After a successful registration, the authenticator is displayed in the main application window.
To delete an authenticator, select it and click Delete authenticator.
For machines with the Windows Logon and ESSO Agent components installed, configure the authentication parameters with group policies.