Lockout policies help prevent adversarial users from gaining unauthorized access to systems through brute-force attacks.
When an authentication lockout occurs, the Nymi Band displays the See Admin icon and prevent the user from performing additional authentication attempts. An authentication lockout occurs in the following scenarios:
- After 50 consecutive failed authentication attempts on a previously enrolled Nymi Band due to a fingerprint mismatch.
- After 3 consecutive failed attempts to complete the fingerprint template during the enrollment due to an issue with the fingerprint imaging.
The lockout persists on the Nymi Band, even if the user removes the Nymi Band. The lockout will also persist while the Nymi Band is dead or while charging.
Clear the lockout by one of the following methods:
- Re-enroll the user to the Nymi Band.
- Authenticate the user with their credentials in the Nymi Band Application. A user can authenticate by using corporate credentials only if the Corporate Credentials Authentication option was enabled in the Nymi Enterprise Server(NES policy at the time of enrollment.
If the user persistently cannot authenticate to the Nymi Band, consider the following actions:
- Restart the Nymi Band and retry authentication.
- Instruct the user to log into the Nymi Band Application while wearing the Nymi Band and authenticate by corporate credentials.
- Delete the user data from the Nymi Band and then disassociate the Nymi Band from the user in NES and Evidian (if used), and then enroll with a different finger.
- Delete the user data from the Nymi Band, disassociate the Nymi Band from the user in NES and Evidian, and then enroll the user with a different Nymi Band.
Comments
0 commentsPlease sign in to leave a comment.