Configuring User Authentication Options
General Options
General options for authentication criteria, device ownership, logon recovery, and restrictions can be found in Preferences > User Authentication > User Authentication.
Option Types
- Authentication Criteria
- Node (MAC+IP) or Device (MAC)
- Authorize IP
- Option to automatically set the IP of the user's initially authenticated endpoint as the allowed authentication IP.
- Available when there is no allowed authentication IP in the user account.
- Authorize MAC
- Option to automatically set the MAC of the user's initially authenticated endpoint as the allowed authentication MAC.
- Available when there is no allowed authentication MAC in the user account.
- Automatic Ownership
- Option to automatically set the IP or device owner, and owner's department information during user authentication.
- Regex for Username
- Option to process authentication by transforming the authenticating user account into a regular expression pattern.
- Hiding Username
- Masks and displays the ID during user authentication.
- Log Out Button
- Option to allow users to directly log out from the agent and CWP page.
- Find Username / Reset Password
- Option to enable/disable the find function when ID or password is lost.
- Verification code valid time
- Option to set the validity period of the SMS sent when using ID/password recovery.
- Displaying Authentication Info
- Option to display authenticated user information in the agent menu and CWP screen.
- User Info for Node Info
- Option to reflect user information (name, description) in the node information of the application PC when a user registration application is approved.
How to Set Authentication Options for Individual Nodes
- Click the node's IP in the node list and select the Policy tab.
- In Node (IP+MAC) Policy, go to User Authentication Policy.
Option Types
- Set user authentication based on node policy.
- Allow all users to authenticate.
- Allow only specified users to authenticate.
How to Set Authentication Policy per Group
The node's authentication policy determines when and how nodes in a specific group authenticate.
To configure options for authentication methods, requirements, time limits, and logon procedures, select the node policy in Policy > Node Policy > [Policy Name] and configure it in Advanced > Authentication Policy.
Option Types
- Authentication Method
- You can select Host Authentication and Password Authentication.
- Password Authentication allows you to specify the allowed authentication source and whether to use 2-factor authentication.
- Authentication Replacement Information
- Active Directory Replaces AD server authentication information with NAC authentication information.
- Integration API Used for agent authentication integration.
- Genian API Used for server-to-server authentication integration using the API provided by Genians Co., Ltd.
- Authenticated User Group
- Sets the user group that will be allowed to authenticate among nodes assigned to the node policy.
- Automatic Logout on Authentication Expiration
- Sets to automatically log out after a specified time from the initial authentication time.
- Automatic Logout for Unused Nodes
- Sets the node to be automatically logged out after a specified time if the node goes down.
- Periodic Re-authentication
- A setting that prompts users to re-authenticate by de-authenticating at specified intervals.
- Notification Before Authentication Expiration
- A setting that notifies the user of authentication expiration via the agent before authentication expires.
- User Authentication Page
- Sets the URL if there is a separate page for user authentication. (If not entered, the system's default authentication page will be displayed.)
- Re-authentication on OS Startup
- A setting that automatically logs out and prompts for re-authentication upon system reboot or waking from sleep.
- Automatic logout during sleep mode is performed according to the Settings > Preferences > Agent > Sleep Mode Restart Time option.
- Does not operate when using authentication replacement information.
- Displayed User Name, Displayed Password
- Enter the text to display in the username and password input fields.