To start the enrollment process, you need to enable and configure the Invite users to create/update Q&A profiles rule. This rule sends email notifications to the users specified in the rule’s scope, inviting them to create or update their Q&A profiles. When configuring email notifications for this rule, you can insert a hyperlink to the Self-Service site. To add the hyperlink, enter the required URL in the email notification body. For example, http://mydomain.com/user. Note, that you cannot specify the hyperlink text.
To configure the Invite users to create/update Q&A profiles enforcement rule, you need to specify the conditions under which users should be notified. For example, users are not registered with Password Manager, users’ answers are shorter than required or users have specified the same answers for several questions. These conditions correspond to the Q&A profile settings that are part of the Q&A policy. For more information, see Configuring Q&A Profile Settings. For more information on configuring this enforcement rule, see Invite Users to Create/Update Profiles.
Note, that only one email notification is sent to each user. If you want to remind users that they should register with Password Manager or update their Q&A profiles and send multiple emails, enable and configure the Remind users to create/update Q&A profiles enforcement rule.
The Remind users to create/update Q&A profiles enforcement rule can notify users via email. When configuring this rule, you can specify several notification scenarios. For each scenario, you should set the time period since the invitation date.
For more information on configuring this enforcement rule, see Remind Users to Create/Update Profiles.
If you want to configure different notification scenarios for different user groups, you can create several Management Policies, and within each Management Policy configure the Remind users to create/update Q&A profiles enforcement rule appropriately for different user groups.
Questions and Answers policy consists of secret questions and Q&A profile settings. Secret questions are questions that users must answer to create their profiles and then use the profiles for authentication. You can create question lists in multiple languages. Each question list contains mandatory, optional, and helpdesk questions. When creating profiles, users must answer all mandatory and helpdesk questions, and a specified number of optional and user-defined questions. You can specify the required number of question in the Q&A profile settings.
When authenticating on the Self-Service site with Q&A profiles, users can use mandatory, optional and user-defined questions from their profiles. When a helpdesk operator authenticates users, the operator can use mandatory and helpdesk questions from users’ profiles.
Q&A profile settings are a collection of settings that define the number of user-defined and optional questions required for registration, minimum length of answers, encryption setting for storing answers, and others.
When you configure the Q&A policy, you should remember that the settings you specify may affect the authentication process. The following authentication activities use the Q&A policy settings:
This activity uses mandatory and helpdesk questions. Helpdesk questions are always stored using reversible encryption. Mandatory questions are hashed, unless you select the Store answers using reversible encryption option in the Q&A profile settings. Note, that if mandatory questions are hashed, you will not be able to use the activity option that specifies that helpdesk operators verify user identity by comparing the answers provided by users with the displayed answers (the Answers to the specified questions (user’s answer is shown) option). For more information, see Authenticate with Q&A Profile.
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Conditions d’utilisation Confidentialité Cookie Preference Center