This section explains how to configure the rollout option in the following two scenarios:
- Organizations where limited administration is required: In this scenario, users are switched to token authentication as soon as a token is registered with their user account. No administration is required.
- Organizations with less Defender users, or where token self-registration is not in use: In this scenario, when a token is registered to the user account, administrative action is required to move users to the correct Active Directory group.
In both the scenarios the following security policies are required:
- Token
- Active Directory password (rollout mode)
To modify Defender Security Policy object properties
- On the computer where the Defender Administration Console is installed, open the Active Directory Users and Computers tool (dsa.msc).
- In the left pane (console tree), expand the appropriate domain node, and then expand the Defender container.
- Click to select the Policies container.
- In the right pane, double-click the Defender Security Policy whose properties you want to modify.
- Use the dialog box that opens to modify the Defender Security Policy properties as necessary.
The dialog box has the following tabs:
- General tab Allows you to configure the Defender Security Policy.
- Account tab Allows you to configure the Defender Security Policy settings related to the lockout of user accounts.
- Expiry tab Allows you to configure expiry settings for Defender passwords and token PINs.
- Logon Hours tab Allows you to configure a time slot when authentication via Defender is permitted or denied to the user.
- SMS Token tab Allows you to configure settings for sending SMS messages containing one-time passwords to users’ SMS-capable devices.
- E-mail Token tab Allows you to configure settings for sending e-mail messages containing one-time passwords to the users.
- GrIDsure Token tab Allows you to enable the use of GrIDsure Personal Identification Pattern (PIP) for authentication via Defender.
- When you are finished, click OK to apply your changes.