Airlock 2FA Settings
repository) futuraeServer) accountDisplayNameProvider) Privacy warning: The display name, when configured, will be stored on Futurae's servers. Sensitive data should therefore not be used as display name.
trustedSessionBindingForActivation) If enabled, activation codes (from a letter or on-screen QR code) can only be used as part of an authenticated session with Airlock IAM. If enabled, activation codes are only accepted together with a "Trusted Session Binding Token". This short-lived token can only be retrieved from an Airlock IAM flow and must be sent to the Futurae server together with the activation code.
This feature ensures that only the intended user can activate a 2FA app/device with a given activation code. The standard Airlock 2FA app does not support this feature, a custom mobile app built using the Futurae SDK is required.
Airlock IAM supports three modes for Trusted Session Binding:
- Never: Trusted Session Binding is disabled.
- Only with Letter: Trusted Session Binding is only enabled for activation letters.
- Always: Trusted Session Binding is enabled both for activation letters and on-screen activation. For on-screen activation, Trusted Session Binding does not provide additional security because the activation code is already bound to an authenticated IAM session, but it could simplify the implementation of the activation process in the mobile app.
trustedSessionBindingForRecovery) trustedSessionBindingValidity) - Trusted Session Binding for Activation is set to "Only with Letter" or "Always".
- Trusted Session Binding for Recovery is enabled.
The duration should not be larger than the "Session Idle Timeout" in the Loginapp, to avoid session timeouts when polling the IAM status.
lockUserOnFraud) LockReason.FraudReportedByUser when reporting a possible fraudulent authentication attempt via the Airlock 2FA app. This is done by rejecting the authentication attempt and then confirming that the attempt was not initiated by the user (in the app dialog).
Self-unlock is possible when locked by this option.
allowFuturaeBypassMode) If enabled, Futurae users that have the bypass mode enabled will be allowed to authenticate / perform approval with IAM. Otherwise, any authentication or approval attempts for users with the bypass mode enabled will result in a failure.
Warning: Enabling bypass mode effectively disables all Airlock 2FA second factor checks. Bypass mode should not be used in production environments.
payloadEncryptionKey) The encryption of payloads in requests to the Futurae API prevents that intermediate infrastructure such as a reverse proxy is able to read or alter the confidential data therein. The encryption key can be obtained from the Futurae Admin Dashboard.
unencryptedPayloadForHWTokens) - If the option is enabled, the payload is transmitted in plain text (unencrypted).
- If the option is disabled, hardware tokens will not be available for authentication or approval via Offline QR Code, since Futurae does not support payload encryption for hardware tokens.
Note: Enabling this property without configuring a 'Payload Encryption Key' has no effect, as the payload is transmitted unencrypted by default.
cooldownPeriod) If configured, a cooldown period is enabled during which a newly registered device cannot be used for certain operations.
By default, all Airlock 2FA steps are configured so that devices may not be used during the "Cooldown Period". Exceptions can be configured directly on the step by de-activating the "Respect Cooldown Period" property.
The duration must be specified in the format "2d 4h 10m 5s" (any part can be omitted).
type: Airlock2FASettings
id: Airlock2FASettings-xxxxxx
displayName:
comment:
properties:
accountDisplayNameProvider:
allowFuturaeBypassMode: false
cooldownPeriod:
futuraeServer:
lockUserOnFraud: false
payloadEncryptionKey:
repository:
trustedSessionBindingForActivation: OFF
trustedSessionBindingForRecovery: false
trustedSessionBindingValidity: 120
unencryptedPayloadForHWTokens: false