What Is an Authentication Source Instance and How to Configure It?
An authentication source instance refers to the authentication source method that an enterprise customer has configured on the iOA console and is currently in use. After configuration, it can be used in identity security policies. When an end user logs in, identity verification is performed through the configured authentication source method.
iOA SaaS currently supports integration with multiple authentication sources, including QR code authentication, SMS authentication, email authentication, IAM authentication, AD authentication, Token authentication, and OTP authentication. For configuration guides on related authentication sources, see Authentication Integration. How to Enable Two-Factor Authentication Policy?
Go to the Identity Security Management > Authentication Policy page and enable two-factor authentication in the authentication policy of the corresponding directory. What Is Challenge Authentication?
Challenge authentication requires users to log in again when they access iOA-integrated businesses under specific conditions, such as time, network location, or the program initiating the access. To implement challenge authentication, perform the following configuration:
1. Go to the Identity Security Management > Authentication Policy page and enable challenge authentication in the authentication policy of the corresponding directory. 2. On the Trusted Access Management > Tunnel Resource Dynamic Access page, configure an access security policy for the selected directory and set the access policy to Access After Challenge Authentication. Where to View Login Logs?
You can click Identity Security Logs > User Login Logs to view the details. Does a User Occupy a Concurrent Account License After Login?
1. After a user logs in and turns on the "Access Company Network" switch in the client, a concurrent account authorization is consumed.
2. You can configure whether users enable the client's company network access switch by default in Identity Security Management > Account Security. |
Show and Disable by Default | The client does not connect to the corporate network upon first login, and users can choose whether to connect in the client. |
Show and Enable by Default | The client automatically connects to the corporate network upon first login, and users can choose whether to connect in the client. |
Hide and enable | Automatically connect to the corporate network and hide the switch. Users cannot change this setting. |
Hide and disable | Do not connect to the corporate network and hide the switch. Users cannot change this setting. |
Record the Switch State Set by Users | If enabled, the NGN switch retains its previous state after the client reconnects. |
PC automatic disconnection during idle time | Enable Automatic PC automatic disconnection during idle time: For scenarios where employees have no business access for an extended period but still occupy company network access resources, the system detects terminal traffic idle duration and automatically disconnects idle connections to release access resources and improve overall resource utilization. Disconnect popup: Two modes are supported: Close automatically after specified duration or Close after manual confirmation, providing flexibility to meet different management requirements. Pop-up content and customization: Display a Pop-up content to employees when disconnection occurs, supporting customizable content in Chinese and English, clearly informing them of the reason for disconnection. |
Mobile terminal automatic disconnection during idle time | Enable Automatic Mobile terminal automatic disconnection during idle time: For scenarios where employees have no business access for an extended period but still occupy company network access resources, the system detects terminal traffic idle duration and automatically disconnects idle connections to release access resources and improve overall resource utilization. Disconnect popup: Two modes are supported: Close automatically after specified duration or Close after manual confirmation, providing flexibility to meet different management requirements. Pop-up content and customization: Display a Pop-up content to employees when disconnection occurs, supporting customizable content in Chinese and English, clearly informing them of the reason for disconnection. |
3. Application scenario description: Administrators can configure whether Remember user-specified switch status as needed. To prevent users from leaving NGN enabled and occupying concurrent resources for a long time, set the switch policy to Disable and disabled default + Do Not Select Remember user-specified switch status. To prioritize user experience and avoid requiring users to manually adjust the switch status each time, set it to Disable and disabled default + Select Remember user-specified switch status.
4. The corresponding client switch location is shown in the following figure.