Bulk Cleanup DIGIPASS wizard

Prev Next

The Bulk Cleanup DIGIPASS wizard helps you to clean up and purge unused authenticators and authenticator instances. It searches for authenticators and/or authenticator instances based on a cleanup strategy and applies a configurable action on them, for example, deleting them.

The wizard schedules a Bulk Cleanup DIGIPASS server task that processes the authenticator instances in the specified search range.

The server task generates a CSV report to provide a complete and detailed summary of the items that were effectively modified (or would have, in case of test runs). Depending on the server task schedule, the report can be downloaded via the Summary page at the end of the wizard or via the Task Management page. If you set a completion notification to Email, the CSV report is also attached to the notification mail.

Available via SERVERS > Bulk Cleanup DIGIPASS.

Before you start the wizard:

  • Ensure that you have administrative access to the OneSpan Authentication Server Administration Web Interface.

  • Ensure that you have the Bulk Cleanup DIGIPASS Data privilege assigned.

Cleanup Strategy

On this page you specify the strategy and search range in the organizational hierarchy to look for unused authenticators and authenticator instances.

Field name

Description

Cleanup strategy

The strategy to determine the items that should be deleted.

Possible values:

  • Instances with reused PNID. Identifies all authenticator instances that have a reused DIGIPASS Push Notification Identifier (PNID) assigned. The PNID is considered reused if another authenticator instance for the same authenticator license exists, which uses the same PNID but has a higher sequence number.

  • Instances without PNID. Identifies all authenticator instances that have no DIGIPASS Push Notification Identifier (PNID) assigned and were never used (last authentication time is not set). The PNID is implicitly set when an authenticator instance is bound to a mobile app. The last authentication time is initially set when the authenticator instance is effectively activated. Having no PNID and no last authentication time set for an authenticator instance, indicates very likely that the activation of that particular instance was not completed.

  • Digipass not used for a specified period. Identifies all authenticators that were not used at least once for a specified number of days (retention period). The usage is determined by the date and time the authenticator was used the last time for a successful authentication. It is only set and updated if the authenticator is assigned and used by the respective user.

  • Digipass disabled for a specified period. Identifies all authenticators and authenticator instances that have been disabled for a specified number of days (retention period). Authenticators and authenticator instances can be explicitly disabled by administrators with the respective privileges.

Domain

Select the domain that you want to search from the list. This will restrict the search to the specified domain only. Select All Domains to search all accessible domains.

Organizational Unit

Select the organizational unit that you want to search from the list. This will restrict the search to the specified organizational unit only. Select All Organizational Units to search all accessible organizational units. Select No Organizational Unit to search only for users, who are not in any organizational unit.

Search downwards in the organizational hierarchy

Specifies whether the specified organizational unit (OU) and all child OUs should be searched.

DIGIPASS Retention

Use this page to specify the retention period for authenticators.

This page is only available if Cleanup strategy is set either to Digipass not used for a specified period or Digipass disabled for a specified period.

Field nameDescription
Retention period in days

In case of Digipass not used for a specified period, this specifies the time period in days during which an authenticator must be used at least once to be considered active. All authenticators with a last authentication date older or equal than this value will be processed. The age is calculated relative to the time when the cleanup task is executed.

In case of Digipass disabled for a specified period, this specifies the time period in days an authenticator or authenticator instance must have been disabled to be processed.

Possible values: 30–65536

Default value: 90

Cleanup Action

On this page you can specify the action that should be applied to the items that were identified by the cleanup strategy.

Field name

Description

Cleanup Action

The action that should be applied to the items that were identified by the cleanup strategy. An overview of the corresponding items is stored in the status information of the respective server task when completed.

Possible values:

  • List matching DIGIPASS and instances. The command searches for authenticators and authenticator instances that match the strategy without modifying any data.

  • Delete matching DIGIPASS and instances. All authenticators and authenticator instances that match the strategy will be deleted.

  • Disable matching DIGIPASS and instances. All authenticators and authenticator instances that match the strategy will be disabled.

Confirmation

Confirm that you really want to continue and delete or disable any authenticators and authenticator instances that match the respective search criteria.

This page is only shown if you have selected any other action than Cleanup Action > List matching DIGIPASS and instances.

Schedule Task

Use this page to specify the task mode and the scheduling settings of the task.

Field name

Description

Task mode

Select on which server you wish to run the server task.

Possible values:

  • Any server. The first server that claims the server task will also run it.

  • This server. Only this server will run the server task.

  • All servers. All running servers will run the server task.

Run immediately

Runs the task now. This will lock the Administration Web Interface session. You will not be able to perform other operations until the task has finished.

Schedule

Runs the task in the background without locking the Administration Web Interface session. You will be able to perform other operations in the Administration Web Interface. It will also allow you to schedule and run the task at a later time.

Notify me of completion by

Specifies whether and how to send notifications when completing the task.

Possible values:

  • None

  • Email

  • SMS

Hour

The time for the task to be run in the 24-hour time format.

The format should be hh:mm:ss.

Date

The date for the task to be run.

The format should be YYYY-MM-DD.

Recurrence Type

Specifies whether the task should be run recurrently.

Possible values:

  • None

  • Daily

  • Monthly

Summary

This page shows the result of the server task.

If you run the task immediately and click Next, the page will display a message that the task has been submitted successfully. You can now open the generated report via OPEN REPORT to display the results in a new window.

If you have scheduled the task, the page will display the schedule details such as start time and notification details. The page will also display a message that the task has been submitted successfully.

Click Finish. You are taken to the Task Management page, where you can verify and manage the server task you have created. You can also download the CSV report with the complete and detailed summary of the items that (would) have been modified.