← Back to plugin index

Migration Selection Step

Description
Selection between different migration subflows depending on configurable options.
Type name
MigrationSelectionStep
Class
com.airlock.iam.authentication.application.configuration.migration.MigrationSelectionStepConfig
May be used by
Properties
Available options (availableOptions)
Description
All available options for this migration selection. For each option, a condition can be configured that determines if it is available in a specific situation and for a particular user. If no option is available the step fails.
Attributes
Plugin-List
Mandatory
Assignable plugins
Never Migrate Possible (neverMigratePossible)
Description
Activate the feature "Never Migrate" allowing the user to permanently reject the migration.

If this property is enabled, it is possible for a user to reject the migration if:

  • No migration date is set for the user OR
  • A migration date is set and the property "Allow 'Never Migrate' Despite Migration Date" is enabled.

Attributes
Boolean
Optional
Default value
false
Never Migrate Possible Despite Migration Date (neverMigratePossibleWithToDate)
Description
Enables the feature "Never Migrate" even if there is a migration date set for the corresponding user.

Whether it is possible to "Never Migrate" depends on whether or not a migration date is set and whether the authentication is happening during the "Never Migrate Period" (if set at all).

Attributes
Boolean
Optional
Default value
false
Never Migrate Period (neverMigratePeriod)
Description

Defines the period before the migration date in which the feature "Never Migrate" is active.

Prerequisites for this property to take effect:
  • A migration date must be set for the user.
  • "Never Migrate Possible" must be enabled.
  • "Never Migrate Possible Despite Migration Date" must be enabled.
  • At least one available option must define a "Hint Period" greater or equal to this property.

If this property is not set, the feature "Never Migrate" is possible (if enabled) during and after the entire "Hint Period".

The duration must be specified in the format "(d)ays (h)ours (m)inutes (s)econds" e.g. "2d 4h 10m 5s" (any part can be omitted).

Attributes
String
Optional
Example
7d
Example
30d
Example
14d 6h 30m
Custom Never Migrate Condition (customNeverMigrateCondition)
Description
By default the "Never Migrate" condition is considered to decide whether it is possible for a user to reject the migration. This default condition can be overwritten by configuring a custom condition.
Attributes
Plugin-Link
Optional
Assignable plugins
Custom Never Migrate Steps (customNeverMigrateSteps)
Description
By default the "Never Migrate" step is executed if the "Never Migrate" condition is fulfilled. This default step can be overwritten by configuring a custom step.
Attributes
Plugin-List
Optional
Assignable plugins
Abort Step Acknowledge Message Step Airlock 2FA Activation Letter Order Step Airlock 2FA Activation Step Airlock 2FA Activation Step (with additional Activation) Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Authentication Step Airlock 2FA Delete Devices Step Airlock 2FA Device Edit Step Airlock 2FA Mobile Only Authentication Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Usernameless Authentication Step Apply Changes Step Complete Migration Step Cronto Activation Step Cronto Authentication Step Cronto Device Reset Step Cronto Letter Order Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Device Token Authentication Step Device Token Registration Step Email Change Verification Step Email Notification Step Email OTP Authentication Step FIDO Authentication Step FIDO Credential Display Name Change Step FIDO Passwordless Authentication Step FIDO Registration Step Failure Step HTTP Basic Authentication Step Kerberos Authentication Step Legacy Email OTP Authentication Step Login From New Device Step Mandatory Password Change Step Matrix Checking Step Migration Selection Step Missing Account Link Step Never Migrate Step No Operation Step OATH OTP Activation Step OATH OTP Authentication Step OAuth 2.0 Consent Step OAuth 2.0 SSO Step OAuth 2.0 Session Reset Step OTP Check via RADIUS Step Password Letter Order Step Password-only Authentication Step Realm Assignment Step Red Flag Raising Step Remember-Me Reset Step Remember-Me Token Generating Step Remember-Me User Identifying Step Representation SSO Ticket Identifying Step Risk Assessment Step Role-based Tag Acquisition Step SAML 2.0 SP User Identifying Step SSI Authentication Step SSI Issuance Step SSI Passwordless Authentication Step SSI Verification Step SSO Ticket Authentication Step Scriptable Step Secret Questions Provisioning Step Selection Step Set Context Data Step Set Password Step Tag Removal Step Terms Of Services Step User Data Edit Step User Identification By Data Step User Identification Step User Identification with FIDO Authentication Step User Lock Step Username Password Authentication Step Username Password with FIDO Authentication Step Vasco OTP Authentication Step Voluntary Password Change Step mTAN Authentication Step mTAN Token Registration Step mTAN Verification Step
Custom Skip Migration Steps (customSkipMigrationSteps)
Description
By default the "No Operation Step" step is executed if the "Skip Migration" condition is fulfilled. This default step can be overwritten by configuring a custom step.
Attributes
Plugin-List
Optional
Assignable plugins
Abort Step Acknowledge Message Step Airlock 2FA Activation Letter Order Step Airlock 2FA Activation Step Airlock 2FA Activation Step (with additional Activation) Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Authentication Step Airlock 2FA Delete Devices Step Airlock 2FA Device Edit Step Airlock 2FA Mobile Only Authentication Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Usernameless Authentication Step Apply Changes Step Complete Migration Step Cronto Activation Step Cronto Authentication Step Cronto Device Reset Step Cronto Letter Order Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Device Token Authentication Step Device Token Registration Step Email Change Verification Step Email Notification Step Email OTP Authentication Step FIDO Authentication Step FIDO Credential Display Name Change Step FIDO Passwordless Authentication Step FIDO Registration Step Failure Step HTTP Basic Authentication Step Kerberos Authentication Step Legacy Email OTP Authentication Step Login From New Device Step Mandatory Password Change Step Matrix Checking Step Migration Selection Step Missing Account Link Step Never Migrate Step No Operation Step OATH OTP Activation Step OATH OTP Authentication Step OAuth 2.0 Consent Step OAuth 2.0 SSO Step OAuth 2.0 Session Reset Step OTP Check via RADIUS Step Password Letter Order Step Password-only Authentication Step Realm Assignment Step Red Flag Raising Step Remember-Me Reset Step Remember-Me Token Generating Step Remember-Me User Identifying Step Representation SSO Ticket Identifying Step Risk Assessment Step Role-based Tag Acquisition Step SAML 2.0 SP User Identifying Step SSI Authentication Step SSI Issuance Step SSI Passwordless Authentication Step SSI Verification Step SSO Ticket Authentication Step Scriptable Step Secret Questions Provisioning Step Selection Step Set Context Data Step Set Password Step Tag Removal Step Terms Of Services Step User Data Edit Step User Identification By Data Step User Identification Step User Identification with FIDO Authentication Step User Lock Step Username Password Authentication Step Username Password with FIDO Authentication Step Vasco OTP Authentication Step Voluntary Password Change Step mTAN Authentication Step mTAN Token Registration Step mTAN Verification Step
Interactive Goto Targets (interactiveGotoTargets)
Description
Manually selectable Goto targets. These are steps to which the user can chose to jump when this is the current flow step.
Attributes
Plugin-List
Optional
Assignable plugins
Dynamic Step Activations (dynamicStepActivations)
Description
Steps that can be dynamically activated while in this step.
Attributes
Plugin-List
Optional
Assignable plugins
Skip Condition (skipCondition)
Description

If this condition is configured and fulfilled, the step is skipped and the flow execution continues with the subsequent step.

Attributes
Plugin-Link
Optional
Assignable plugins
Pre Condition (preCondition)
Description
This step is executed only if the configured pre condition is fulfilled. If the condition is not fulfilled, the step and flow execution fail immediately. The step is not initialized and no step method can be called. If no condition is configured, the behavior is that of a fulfilled pre condition.
Attributes
Plugin-Link
Optional
Assignable plugins
Requires Activation (requiresActivation)
Description
If enabled, this step is only executed if it has been dynamically activated from a previous step. If it has not been activated, the step is skipped (equivalent to when the skip condition is fulfilled).
Attributes
Boolean
Optional
Default value
false
Step ID (stepId)
Description
ID of this step. This is only needed if this step is the target of a goto action or if this step requires activation.
Attributes
Plugin-Link
Optional
Assignable plugins
On Failure Gotos (onFailureGotos)
Description

If the step fails (no retry) and a goto target for the error code is defined here, the flow does not fail and instead a "goto" to the specified target step is executed. Note that even when the "goto" is executed, any error codes that are considered a failed factor attempt will still increment the "failed attempts" counter, and may lead to the user being locked. Therefore, this may still result in a failed flow.

A typical application of this feature is switching to an alternative authentication factor step, if an external service (e.g. Futurae server, SMS gateway) is not available (error code EXTERNAL_SERVICE_UNAVAILABLE with "Strict Counting" disabled, which will not increment the "failed attempts" counter). Other error codes can be found in the IAM REST documentation, in both the general "Error Codes" section and in the documentation of specific endpoints.

Attributes
Plugin-Map
Optional
Assignable plugins
Custom Response Attributes (customResponseAttributes)
Description

A list of custom attributes that are returned in the REST response in addition to the standard attributes the step already returns. The custom attributes defined here are only returned if the step result does not lead to an error response.

Custom attributes are added to the response when a step is initialized and when actions are executed on the step. They will therefore be available in the response leading to this step, and in any responses from endpoints specific to this step. For non-interactive steps, custom attributes are accumulated and added to the response leading to the next interactive step.

Custom attributes are not returned for 'retrieve' endpoints.

Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: MigrationSelectionStep
id: MigrationSelectionStep-xxxxxx
displayName: 
comment: 
properties:
  availableOptions:
  customFailureResponseAttributes:
  customNeverMigrateCondition:
  customNeverMigrateSteps:
  customResponseAttributes:
  customSkipMigrationSteps:
  dynamicStepActivations:
  interactiveGotoTargets:
  neverMigratePeriod:
  neverMigratePossible: false
  neverMigratePossibleWithToDate: false
  onFailureGotos:
  preCondition:
  requiresActivation: false
  skipCondition:
  stepId: