Your suggested change has been received. Thank you.

close

Suggest A Change

https://thales.na.market.dpondemand.io/docs/dpod/services/kmo….

back

SafeNet Trusted Access

Tokens

search

Tokens

Tokens

You can view your registered tokens on the Tokens tab. The token list includes information such as the token type, token state, serial number, container, and user ID.

Token states

View a count of all token types in the account's inventory by state.

  • On the STA Token Management console, select Snapshot > Token States.

alt_text

Token state Description
Initialize A hardware token in inventory that must be initialized before it becomes available for assignment.
Inventory The token is available for assignment to users.
Assigned The token is no longer in inventory. It has either been manually assigned to a user but not activated, or is part of a bulk provisioning operation and has not yet been enrolled by a user.
Active The token can be used to authenticate. It is assigned to a user and has been enrolled or used to authenticate.
Suspended The token cannot be used to authenticate until it is reactivated or unlocked by an operator. It remains assigned to a user. Tokens are usually suspended if there is a security concern, such as a lost or misplaced token.
Locked The token cannot be used to authenticate until the unlock policy is triggered or until the token is reactivated by an operator. This state occurs when a user exceeds the maximum consecutive failed logon attempts threshold. The automatic locking and unlocking of tokens is controlled by the Account Lockout/Unlock Policy.
Lost / Faulty This is a state applied by an operator when revoking a token. Revoked tokens are returned to Inventory in this state where they can be permanently removed or if the token is subsequently found or determined to function properly, it can be reinitialized into the Inventory state.

Search for tokens

Search for your registered tokens and then manage tokens from the Token List, such as move tokens to a different container, reset the PIN policy, or delete.

  1. On the STA Token Management console, select Tokens > Tokens.

    alt_text

  2. Enter the search criteria.

    Search field Description
    Token Type Refine the list to a specific type of token.
    State Refine the list to tokens in a selected state.
    Serial # Search by partial or complete serial number to find a range or specific token.
    Container Lists only the tokens that are held in the selected container.
  3. Select Search.

    alt_text

  4. Manage the tokens as required:

    • Move—Select tokens and then click Move to place them in a different container.

    • Reset PIN Policy—Apply the current Server-side PIN policy to the selected range of tokens. This function is not available for tokens initialized with Token-side PINs. Tokens must be in the Inventory state.

    • Delete—Select tokens and then click Delete to remove them from the Virtual Server Inventory. Delete cannot be used with rented tokens. Rented tokens must be deallocated by the Service Provider.

    • User ID—Click to access the user’s record and management functions. The additional Assignment modules display.

    • Serial Number—Click to display the token operating parameters, in-use statistics, organizational ownership, and MobilePASS app details (the target OS, Push OTP state, and the device type). Under Mobile App, the Push OTP field displays only if the push feature is enabled in Policy > Token Policies. If the push feature is enabled, the state of the Push OTP feature is displayed here. The states are:

      • Enabled—Displays if the user has permitted Push OTP notifications on the device.

      • Disabled— Displays if the user has not permitted Push OTP notifications on the device, but the application is push capable (for example, on MobilePASS+).

      • Not Applicable— Displays if the application is not push capable (for example, on MobilePASS 8).

  5. To display token details, select the serial # of the token from the list of search results.

    alt_text

View the token change log

Display the last five token management operations in the virtual server. The log displays a row for each token operation that includes the token serial number, the action, a date/time stamp of the operation, the name of the operator who performed the action, the organization to which the operator belongs (for example, your organization or service provider), and any comment provided by the operator.

  1. On the STA Token Management console, select Tokens.

  2. Do one of the following:

    • Select Tokens and then select Change Log.

    • In the Shortcuts pane, select View Change Log.

    alt_text

List locked tokens (shortcut)

A token changes to a locked state when a user exceeds the maximum consecutive failed logon attempts threshold. A locked token can be reactivated by an Operator. The automatic locking and unlocking of tokens is controlled by the Account Lockout/Unlock Policy.

To display details about tokens that are locked due to excessive consecutive failed authentication attempts (State = Locked):

  • On the STA Token Management console, select Shortcuts > List Locked Tokens.

List lost tokens

A token is changed to a lost state by the operator when revoking a token. A revoked token is returned to inventory in this state where it can be permanently removed or, if the token is subsequently found or determined to function properly, reinitialized into the inventory state.

To display details about tokens that have been placed in a lost or failed state by the operator (State = Lost/Failed):

  • On the STA Token Management console, select Shortcuts > List Lost Tokens.